Junglewise Threat Intelligence

CVE-2026-27220: Adobe Acrobat Reader use-after-free in file parsing

CVE-2026-27220 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is widely used to open and view PDF documents in both personal and enterprise environments. A use-after-free vulnerability in versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier could allow an attacker to execute arbitrary code on a user's computer if they trick the user into opening a malicious PDF file. This could lead to complete compromise of the affected system, including theft of sensitive data or installation of malware.

Technical details

A use-after-free vulnerability exists in Adobe Acrobat Reader's file parsing logic, affecting versions through 25.001.21265. The vulnerability is triggered when processing a specially crafted PDF file, allowing an attacker to dereference freed memory and execute arbitrary code in the context of the current user. Exploitation requires user interaction—the victim must open a malicious PDF file. This is a memory corruption vulnerability with high impact, as it bypasses normal security boundaries and enables arbitrary code execution. The vendor has been notified and patches are expected to be released through the APSB26-26 advisory.

Affected products

  • Adobe Acrobat Reader 24.001.30307, 24.001.30308, 25.001.21265 and earlier

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: APSB26-26 security update released

References

Related threats