Description
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure
Action: Apply Patch
AI Analysis

Impact

Acrobat Reader contains an out‑of‑bounds read flaw that can expose sensitive memory contents. When a malicious file is processed, the application may read data beyond the intended buffer, resulting in leakage of private data. The vulnerability specifically enables disclosure of contents in the victim’s memory space, compromising confidentiality.

Affected Systems

Adobe products affected include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. No specific version numbers are listed in the CNA data; the CVE affects all current releases of these products.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. Because exploitation requires the user to open a malicious file, the attack vector is user‑initiated and likely involves social engineering. The EPSS score is unknown, and the flaw is not yet listed in CISA’s KEV catalog. Consequently, the risk is moderate but non‑zero, and timely remediation is advised.

Generated by OpenCVE AI on September 9, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe security update that addresses the out‑of‑bounds read issue
  • Disable automatic processing of PDF files from untrusted sources or require explicit user approval before opening them
  • Implement PDF file validation or sandboxing to prevent malicious content from executing within the application

Generated by OpenCVE AI on September 9, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Vendors & Products Adobe acrobat 2024

Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:28:28.296Z

Reserved: 2026-08-27T21:20:45.365Z

Link: CVE-2026-81982

cve-icon Vulnrichment

Updated: 2026-09-11T21:28:23.683Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:44.747

Modified: 2026-09-11T22:16:44.773

Link: CVE-2026-81982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T04:30:19Z

Weaknesses