
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27220 is a Use After Free (UAF) vulnerability in Adobe Acrobat Reader and Acrobat DC that can result in arbitrary code execution in the context of the current user. It affects Acrobat Reader DC and Acrobat DC versions up to and including 25.001.21265 (Continuous track) and Acrobat Classic versions up to and including 24.001.30308. Adobe disclosed and patched this vulnerability on March 10, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, ZDI Advisory).
The vulnerability is classified as CWE-416 (Use After Free), meaning the application references memory after it has been freed, potentially allowing an attacker to control program execution flow. Exploitation requires a victim to open a specially crafted malicious PDF file, making the attack vector local with required user interaction. No authentication is required on the part of the attacker — the social engineering component (delivering a malicious file) is the primary precondition. A ZDI advisory (ZDI-26-355) describes the flaw generically but does not provide exploit code or reproduction steps (ZDI Advisory, Adobe Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe Acrobat Reader or Acrobat DC. The impact spans confidentiality, integrity, and availability — all rated High — meaning an attacker could read sensitive data, modify files, or disrupt application functionality within the user's context. Because the exploit runs at user privilege level, further lateral movement would depend on the victim's account permissions, but the vulnerability could serve as an initial access vector in a broader attack chain (Adobe Advisory, Feedly).
%TEMP%, /tmp) shortly after opening a PDF; new executables or scripts created by the Acrobat Reader process.AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl, wget); Acrobat processes making unexpected network connections.Adobe has released patched versions addressing this vulnerability: update Acrobat Reader DC and Acrobat DC (Continuous track) to version 25.001.21288 or later, and Acrobat Classic to version 24.001.30356 or later. Users should apply these updates immediately via Adobe's built-in updater or through enterprise patch management tools. As a precautionary measure, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider application allowlisting or restricting PDF handling to sandboxed environments (Adobe Advisory, CIS Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Sophos covered the March 2026 patch cycle, noting Adobe's broad patch release across 15 product families (Sophos Blog). FortiGuard updated its IPS signatures to detect exploitation attempts related to this CVE. Community reaction has been measured given the absence of active exploitation, with general consensus that patching is the appropriate response.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."