Junglewise Threat Intelligence

CVE-2026-47965: Adobe Acrobat Reader out-of-bounds write

CVE-2026-47965 · Severity: high · CVSS 7.8 · Published 2026-06-12

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in certain versions allows an attacker to take control of a user's computer if the user opens a specially crafted, malicious PDF file. This could lead to the theft of sensitive information or the installation of unauthorized software.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw is triggered when the application improperly handles memory during the processing of a PDF file. An attacker can exploit this by convincing a user to open a specifically crafted malicious file (User Interaction required). Successful exploitation allows for arbitrary code execution in the context of the current user, potentially leading to full system compromise. Adobe has addressed this in advisory APSB26-63.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory: Adobe security bulletin APSB26-63 published

References

Related threats