CVE-2026-47914
Adobe Acrobat Classic vulnerability analysis and mitigation

Overview

CVE-2026-47914 is a Use After Free (UAF) vulnerability in Adobe Acrobat and Acrobat Reader that could allow arbitrary code execution in the context of the current user. It affects Adobe Acrobat and Acrobat Reader versions 26.001.21651 and earlier, as well as Acrobat 2024 versions 24.001.30365 and earlier, on both Windows and macOS. The vulnerability was disclosed and patched on June 9, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, ZDI).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), arising from the lack of validation of an object's existence prior to performing operations on it — a memory safety flaw that can lead to code execution when freed memory is subsequently accessed. The attack vector is local, requiring no privileges but necessitating user interaction: a victim must open a specially crafted malicious PDF file. The Zero Day Initiative notes that the issue results from the application failing to validate the existence of an object before performing operations on it, which remote attackers can leverage to execute arbitrary code (ZDI, Adobe Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe Acrobat Reader, resulting in high confidentiality, integrity, and availability impact. An attacker who tricks a victim into opening a malicious PDF file could gain full control of the affected user session, potentially enabling data theft, installation of malware, or further lateral movement within the victim's environment. The scope is limited to the current user context and does not involve privilege escalation beyond the running process (Adobe Advisory, ZDI).

Mitigation and workarounds

Adobe released security updates on June 9, 2026, addressing this vulnerability. Users should update to Adobe Acrobat and Acrobat Reader version 26.001.21662 or later (for the current track), or Acrobat 2024 version 24.001.30383 or later (for the Classic track), on both Windows and macOS. As a general precaution, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider implementing sandboxing or file-type restrictions for PDF processing where feasible (Adobe Advisory).

Community reactions

Adobe issued a formal security bulletin (APSB26-63) on June 9, 2026, as part of its June 2026 patch cycle covering multiple products. The Zero Day Initiative published a coordinated disclosure advisory (ZDI-26-348) on the same date. Coverage was picked up by security aggregators including CISA's weekly vulnerability bulletin and threat intelligence platforms such as Tenable and VulnDB, but no significant independent researcher commentary or social media discussion has been identified (Adobe Advisory, ZDI).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-48294HIGH7.4
  • Adobe Acrobat Classic logoAdobe Acrobat Classic
  • cpe:2.3:a:adobe:acrobat
NoNoJun 17, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management