Junglewise Threat Intelligence

CVE-2026-48373: Adobe Acrobat Reader heap overflow in PDF parsing

CVE-2026-48373 · Severity: high · CVSS 7.8 · Published 2026-07-17

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where an attacker can take control of a user's computer if the user is tricked into opening a specially crafted, malicious PDF file. This could lead to unauthorized access to sensitive data or the installation of malicious software on the victim's system.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe Acrobat Reader. The vulnerability is triggered when the application improperly handles memory allocation while processing a specially crafted PDF file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Affected versions include those up to 24.001.30365 and 26.001.21651; users should refer to Adobe advisory APSB26-63 for patching information.

Affected products

  • Adobe Acrobat Reader <= 24.001.30365, <= 26.001.21651

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory: Adobe published security bulletin APSB26-63

References

Related threats