Description
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Application Denial of Service
Action: Update
AI Analysis

Impact

Acrobat Reader is vulnerable to uncontrolled resource consumption. The flaw, labeled as CWE-400, occurs when the application processes a specially crafted file, potentially exhausting CPU, memory or disk space. This resource exhaustion can cause the application to become unresponsive or terminate, resulting in a denial‑of‑service condition for the end user. The vulnerability does not grant the attacker additional privileges, modify data, or read confidential information.

Affected Systems

Adobe offers the affected products in its lineup under several product names. The flaw affects Adobe Acrobat Reader, Adobe Acrobat, and the 2024 edition of Acrobat. No specific patch version is listed, but users operating version 2024 or later should check Adobe’s security advisory for updates. The security notice does not isolate sub‑versions, so all releases within the mentioned product families are considered vulnerable.

Risk and Exploitability

With a CVSS score of 5.5, the vulnerability is rated as moderate. EPSS data is unavailable, and the flaw is not in CISA KEV, indicating no known active exploitation reports. Exploitation requires user interaction – the victim must open a malicious PDF. The attack path thus depends on social engineering or phishing vectors. Given the lack of remote access requirements and the controlled user interaction needed, the overall risk remains moderate.

Generated by OpenCVE AI on September 9, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat Reader update once available
  • Educate users to avoid opening unknown or suspicious PDF files
  • Configure the application to restrict automatic opening of PDF documents from untrusted sources

Generated by OpenCVE AI on September 9, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Uncontrolled Resource Consumption (CWE-400)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:27:59.574Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-82001

cve-icon Vulnrichment

Updated: 2026-09-11T21:27:55.501Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:46.637

Modified: 2026-09-11T22:16:45.267

Link: CVE-2026-82001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:31Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption