Junglewise Threat Intelligence

CVE-2026-47915: Adobe Acrobat Reader use after free in PDF parsing

CVE-2026-47915 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious PDF file could allow an attacker to run unauthorized code on your computer. This could lead to a full system compromise or the theft of sensitive information stored on the device.

Technical details

A Use After Free (UAF) vulnerability (CWE-416) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, which can be leveraged to corrupt memory. An attacker can exploit this by tricking a user into opening a specifically crafted PDF document. Successful exploitation allows for arbitrary code execution in the context of the current user. The vulnerability is tracked as APSB26-63 by the vendor.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier versions

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-63 published

References

Related threats