Junglewise Threat Intelligence

CVE-2026-47959: Adobe Acrobat Reader stack-based buffer overflow

CVE-2026-47959 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in certain versions allows an attacker to take control of a user's computer if the user is tricked into opening a specially crafted, malicious PDF file. This could lead to unauthorized access to personal data or the installation of malicious software on the victim's system.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw is triggered when the application improperly handles memory while processing a specially crafted PDF file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R) but no prior privileges (PR:N). Adobe has addressed this in security bulletin APSB26-63.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-63 published

References

Related threats