
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47965 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that could result in arbitrary code execution in the context of the current user. It affects Acrobat Reader and Adobe Acrobat DC (Continuous track) versions up to and including 26.001.21651, and Acrobat 2024 (Classic track) versions up to and including 24.001.30365, on both Windows and macOS. The vulnerability was disclosed by Adobe on June 9, 2026, and published to the NVD on June 12, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during PDF file processing. Exploitation requires a local attack vector — an attacker must deliver a specially crafted malicious PDF file and convince a victim to open it, triggering the out-of-bounds write condition. No privileges are required on the part of the attacker, but user interaction is mandatory. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Acrobat Reader, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access sensitive documents, install malware, modify files, or use the compromised session as a foothold for lateral movement within a network. The scope is limited to the current user's context, but in environments where users operate with elevated privileges, the impact could extend further (GitHub Advisory, Adobe Advisory).
AcroRd32.exe or Acrobat.exe) to unknown external IP addresses or domains shortly after a PDF is opened.AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl, wget, or scripting interpreters).%TEMP%, /tmp) or startup folders following PDF file access; new or modified executables in user-writable locations.Adobe has released patched versions addressing this vulnerability: users should update to Acrobat DC / Acrobat Reader DC version 26.001.21652 or later (Continuous track) and Acrobat 2024 version 24.001.30366 or later (Classic track) on both Windows and macOS. Updates can be applied via the built-in updater (Help > Check for Updates) or through Adobe's enterprise deployment mechanisms. As an interim measure, users should exercise caution when opening PDF files from untrusted sources, and organizations may consider restricting Acrobat Reader execution in high-security environments or enabling Protected Mode/Protected View (Adobe Advisory).
The vulnerability was referenced in a CISA vulnerability bulletin (SB26-166) published on June 15, 2026, indicating routine tracking by U.S. government cybersecurity authorities. Aggregator sites including VulnDB, CVEFeed, and Radar by Offseq indexed the vulnerability shortly after disclosure, reflecting standard community monitoring. No notable independent researcher commentary, vendor statements beyond the Adobe advisory, or significant social media discussion has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."