Description
Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch if available
AI Analysis

Impact

Acrobat Reader contains a use‑after‑free flaw that can expose sensitive data stored in memory. It is a memory‑corruption issue that does not provide code execution but can leak private information. An attacker could craft a malicious file that, when opened, causes the application to read freed memory and disclose its contents.

Affected Systems

Affected products include Adobe Acrobat 2024, Adobe Acrobat Reader, and the Adobe Acrobat family. Version details are not specified, but any installation of the listed products that predates the latest security update is susceptible.

Risk and Exploitability

The CVSS score of 5.5 reflects a moderate risk to confidentiality. EPSS data are unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited at present. Successful exploitation requires user interaction: a victim must open a crafted PDF file. Attackers would need to deliver or convince the victim to open such a file, limiting the attack surface but still presenting a tangible threat to organizations handling sensitive documents.

Generated by OpenCVE AI on September 9, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat and Acrobat Reader security update or upgrade to the newest release to remove the use‑after‑free flaw.
  • Configure Adobe Reader’s security settings to disable JavaScript execution and other active content in PDFs, thereby reducing the risk that a malicious file can access or manipulate memory.
  • Avoid opening PDF files from untrusted or unknown sources, and use email‑content filtering or sandboxing tools to inspect attachments before user interaction.

Generated by OpenCVE AI on September 9, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Use After Free (CWE-416)
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T14:58:58.363Z

Reserved: 2026-08-27T21:20:45.365Z

Link: CVE-2026-81984

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:20.543Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:44.977

Modified: 2026-09-10T15:17:47.210

Link: CVE-2026-81984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T00:00:05Z

Weaknesses