CVE-2026-47965
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2026-47965 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that could result in arbitrary code execution in the context of the current user. It affects Acrobat Reader and Adobe Acrobat DC (Continuous track) versions up to and including 26.001.21651, and Acrobat 2024 (Classic track) versions up to and including 24.001.30365, on both Windows and macOS. The vulnerability was disclosed by Adobe on June 9, 2026, and published to the NVD on June 12, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during PDF file processing. Exploitation requires a local attack vector — an attacker must deliver a specially crafted malicious PDF file and convince a victim to open it, triggering the out-of-bounds write condition. No privileges are required on the part of the attacker, but user interaction is mandatory. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Acrobat Reader, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access sensitive documents, install malware, modify files, or use the compromised session as a foothold for lateral movement within a network. The scope is limited to the current user's context, but in environments where users operate with elevated privileges, the impact could extend further (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Craft malicious PDF: An attacker creates a specially crafted PDF file designed to trigger an out-of-bounds write condition in the vulnerable Acrobat Reader PDF parsing engine.
  2. Deliver the file: The attacker distributes the malicious PDF via phishing email, malicious website download, shared network drive, or other social engineering methods to reach a target running a vulnerable version of Acrobat Reader.
  3. Victim opens the file: The victim opens the malicious PDF using an affected version of Adobe Acrobat Reader (≤26.001.21651 or ≤24.001.30365), triggering the out-of-bounds write vulnerability during file parsing.
  4. Achieve code execution: The memory corruption caused by the out-of-bounds write is leveraged to redirect execution flow, enabling arbitrary code execution in the context of the current user — potentially deploying a payload such as a reverse shell, ransomware, or credential stealer (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Acrobat Reader process (AcroRd32.exe or Acrobat.exe) to unknown external IP addresses or domains shortly after a PDF is opened.
  • Process: Unusual child processes spawned by AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl, wget, or scripting interpreters).
  • File System: Unexpected files written to user temp directories (%TEMP%, /tmp) or startup folders following PDF file access; new or modified executables in user-writable locations.
  • Logs: Application crash logs or Windows Error Reporting entries referencing Acrobat Reader with memory access violations; security event logs showing process creation events with Acrobat as the parent process.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: users should update to Acrobat DC / Acrobat Reader DC version 26.001.21652 or later (Continuous track) and Acrobat 2024 version 24.001.30366 or later (Classic track) on both Windows and macOS. Updates can be applied via the built-in updater (Help > Check for Updates) or through Adobe's enterprise deployment mechanisms. As an interim measure, users should exercise caution when opening PDF files from untrusted sources, and organizations may consider restricting Acrobat Reader execution in high-security environments or enabling Protected Mode/Protected View (Adobe Advisory).

Community reactions

The vulnerability was referenced in a CISA vulnerability bulletin (SB26-166) published on June 15, 2026, indicating routine tracking by U.S. government cybersecurity authorities. Aggregator sites including VulnDB, CVEFeed, and Radar by Offseq indexed the vulnerability shortly after disclosure, reflecting standard community monitoring. No notable independent researcher commentary, vendor statements beyond the Adobe advisory, or significant social media discussion has been identified for this CVE.

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management