
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47914 is a Use After Free (UAF) vulnerability in Adobe Acrobat and Acrobat Reader that could allow arbitrary code execution in the context of the current user. It affects Adobe Acrobat and Acrobat Reader versions 26.001.21651 and earlier, as well as Acrobat 2024 versions 24.001.30365 and earlier, on both Windows and macOS. The vulnerability was disclosed and patched on June 9, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, ZDI).
The vulnerability is classified as CWE-416 (Use After Free), arising from the lack of validation of an object's existence prior to performing operations on it — a memory safety flaw that can lead to code execution when freed memory is subsequently accessed. The attack vector is local, requiring no privileges but necessitating user interaction: a victim must open a specially crafted malicious PDF file. The Zero Day Initiative notes that the issue results from the application failing to validate the existence of an object before performing operations on it, which remote attackers can leverage to execute arbitrary code (ZDI, Adobe Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe Acrobat Reader, resulting in high confidentiality, integrity, and availability impact. An attacker who tricks a victim into opening a malicious PDF file could gain full control of the affected user session, potentially enabling data theft, installation of malware, or further lateral movement within the victim's environment. The scope is limited to the current user context and does not involve privilege escalation beyond the running process (Adobe Advisory, ZDI).
Adobe released security updates on June 9, 2026, addressing this vulnerability. Users should update to Adobe Acrobat and Acrobat Reader version 26.001.21662 or later (for the current track), or Acrobat 2024 version 24.001.30383 or later (for the Classic track), on both Windows and macOS. As a general precaution, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider implementing sandboxing or file-type restrictions for PDF processing where feasible (Adobe Advisory).
Adobe issued a formal security bulletin (APSB26-63) on June 9, 2026, as part of its June 2026 patch cycle covering multiple products. The Zero Day Initiative published a coordinated disclosure advisory (ZDI-26-348) on the same date. Coverage was picked up by security aggregators including CISA's weekly vulnerability bulletin and threat intelligence platforms such as Tenable and VulnDB, but no significant independent researcher commentary or social media discussion has been identified (Adobe Advisory, ZDI).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."