Junglewise Threat Intelligence

CVE-2026-47917: Adobe Acrobat Reader use after free vulnerability

CVE-2026-47917 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious file could allow an attacker to take control of the user's computer. This could lead to the theft of sensitive information or the installation of unauthorized software.

Technical details

A Use After Free (UAF) vulnerability (CWE-416) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw is triggered when the application improperly manages memory during the processing of PDF content. An attacker can exploit this by convincing a user to open a specifically crafted malicious PDF file. Successful exploitation allows for arbitrary code execution in the context of the current user, potentially leading to full system compromise. The attack vector is classified as local because it requires the file to be opened on the target system, and user interaction is required.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe released security bulletin APSB26-63

References

Related threats