CVE-2026-27220
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2026-27220 is a Use After Free (UAF) vulnerability in Adobe Acrobat Reader and Acrobat DC that can result in arbitrary code execution in the context of the current user. It affects Acrobat Reader DC and Acrobat DC versions up to and including 25.001.21265 (Continuous track) and Acrobat Classic versions up to and including 24.001.30308. Adobe disclosed and patched this vulnerability on March 10, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, ZDI Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), meaning the application references memory after it has been freed, potentially allowing an attacker to control program execution flow. Exploitation requires a victim to open a specially crafted malicious PDF file, making the attack vector local with required user interaction. No authentication is required on the part of the attacker — the social engineering component (delivering a malicious file) is the primary precondition. A ZDI advisory (ZDI-26-355) describes the flaw generically but does not provide exploit code or reproduction steps (ZDI Advisory, Adobe Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe Acrobat Reader or Acrobat DC. The impact spans confidentiality, integrity, and availability — all rated High — meaning an attacker could read sensitive data, modify files, or disrupt application functionality within the user's context. Because the exploit runs at user privilege level, further lateral movement would depend on the victim's account permissions, but the vulnerability could serve as an initial access vector in a broader attack chain (Adobe Advisory, Feedly).

Exploitation steps

  1. Craft a malicious PDF: An attacker creates a specially crafted PDF file designed to trigger the use-after-free condition in Adobe Acrobat Reader's PDF parsing engine, exploiting the freed memory reference to redirect execution flow.
  2. Deliver the malicious file: The attacker distributes the PDF via phishing email, malicious download link, or other social engineering methods to convince the target user to open the file.
  3. Victim opens the file: The victim opens the malicious PDF in a vulnerable version of Adobe Acrobat Reader DC (≤25.001.21265) or Acrobat Classic (≤24.001.30308).
  4. Trigger the UAF condition: Opening the file causes the vulnerable code path to reference previously freed memory, allowing the attacker to control the instruction pointer or corrupt heap structures.
  5. Achieve code execution: The attacker's shellcode or ROP chain executes arbitrary code in the context of the current user, potentially dropping malware, establishing persistence, or exfiltrating data (ZDI Advisory, Adobe Advisory).

Indicators of compromise

  • File System: Unexpected files written to user temp directories (e.g., %TEMP%, /tmp) shortly after opening a PDF; new executables or scripts created by the Acrobat Reader process.
  • Process: Unusual child processes spawned by AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl, wget); Acrobat processes making unexpected network connections.
  • Network: Outbound connections from Acrobat Reader to unknown or suspicious IP addresses or domains immediately following PDF file open events.
  • Logs: Windows Event Logs showing process creation events (Event ID 4688) with Acrobat as the parent process and unexpected child processes; application crash logs or Dr. Watson/WER reports associated with Acrobat around the time of exploitation.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: update Acrobat Reader DC and Acrobat DC (Continuous track) to version 25.001.21288 or later, and Acrobat Classic to version 24.001.30356 or later. Users should apply these updates immediately via Adobe's built-in updater or through enterprise patch management tools. As a precautionary measure, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider application allowlisting or restricting PDF handling to sandboxed environments (Adobe Advisory, CIS Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Sophos covered the March 2026 patch cycle, noting Adobe's broad patch release across 15 product families (Sophos Blog). FortiGuard updated its IPS signatures to detect exploitation attempts related to this CVE. Community reaction has been measured given the absence of active exploitation, with general consensus that patching is the appropriate response.

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management