Description
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Acrobat Reader contains an out-of-bounds read vulnerability that can reveal sensitive memory contents. The flaw occurs when processing a malicious file crafted by an attacker, and its exploitation requires the user to open the file. Successful exploitation would expose confidential data to the attacker, compromising confidentiality.

Affected Systems

Adobe Acrobat 2024, Adobe Acrobat Reader and generic Adobe Acrobat products are affected. No specific version numbers are listed in the CNA data, so all builds within the mentioned product line must be considered at risk.

Risk and Exploitability

This issue has a CVSS score of 5.5, indicating a moderate severity. The exploit probability (EPSS) is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector involves user interaction: the victim must open a malicious file. Because the adversary needs only a social‑engineering step to get the file opened, the likelihood of exploitation depends on user behavior, but the potential impact is the disclosure of sensitive information if the exploit succeeds.

Generated by OpenCVE AI on September 9, 2026 at 08:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat/Reader security update referenced in the Adobe advisory.
  • Avoid opening or executing files obtained from untrusted or unknown sources.
  • Implement application whitelisting or sandboxing to limit Acrobat Reader's ability to access arbitrary memory.

Generated by OpenCVE AI on September 9, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:35:16.289Z

Reserved: 2026-08-27T21:20:45.366Z

Link: CVE-2026-81991

cve-icon Vulnrichment

Updated: 2026-09-09T13:35:13.332Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:45.850

Modified: 2026-09-10T13:43:17.313

Link: CVE-2026-81991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:45:17Z

Weaknesses