Junglewise Threat Intelligence

CVE-2026-47919: Adobe Acrobat Reader use after free vulnerability

CVE-2026-47919 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious PDF file could allow an attacker to take control of the user's computer. This could lead to the theft of sensitive information, unauthorized software installation, or disruption of business operations.

Technical details

A Use After Free (UAF) vulnerability (CWE-416) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this by tricking a user into opening a specifically crafted PDF document. Successful exploitation allows for arbitrary code execution in the context of the current user. The attack requires user interaction (UI:R) and is delivered via a local vector (AV:L), typically through email or web downloads.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier

Timeline

  • 2026-06-09: disclosed: Initial publication of the CVE record and Adobe advisory APSB26-63.

References

Related threats