Description
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow has been discovered in Adobe Acrobat Reader and Adobe Acrobat. The flaw allows an attacker to execute arbitrary code within the victim’s user context when a malicious file is opened, potentially leading to data compromise, system takeover, or further lateral movement.

Affected Systems

Affected products are Adobe Acrobat 2024 and Adobe Acrobat Reader, all current releases of these packages are vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. Exploitation requires the user to interact by opening a crafted PDF, which is why the attack likelihood depends on user behavior and the presence of file restrictions. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so there is no documented public exploitation yet, but the high impact and reasonable ease of delivery warrant urgent attention.

Generated by OpenCVE AI on September 9, 2026 at 09:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat Reader update that resolves the heap overflow problem.
  • Configure Acrobat to disallow JavaScript and reduce automatic execution of content in PDFs if not required for legitimate use.
  • Enforce strict file trusted list policies and scan incoming PDF documents with antivirus or sandboxing tools before they are opened by end users.

Generated by OpenCVE AI on September 9, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T13:07:15.672Z

Reserved: 2026-08-27T21:20:45.366Z

Link: CVE-2026-81992

cve-icon Vulnrichment

Updated: 2026-09-10T13:00:53.157Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:45.980

Modified: 2026-09-10T15:57:31.813

Link: CVE-2026-81992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:23Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow