Technology · Adobe
Adobe Acrobat vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 63 vulnerabilities in Adobe Acrobat: 0 in the last 7 days and 31 in the last 90 days, 27 of them critical and 27 exploited in the wild. The most recent, CVE-2026-82001, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 31
- Critical, all time
- 27
- Exploited in the wild
- 27
About Adobe Acrobat
A family of application software and Web services to view, create, manipulate, print and manage files in Portable Document Format.
Latest Adobe Acrobat vulnerabilities
- CVE-2026-82001: Adobe Acrobat Reader denial-of-service via uncontrolled resource consumptionmediumCVSS 5.5EPSS 0.2%
- CVE-2026-81996: Adobe Acrobat Reader privilege escalation via incorrect authorizationhighCVSS 8.8EPSS 0.2%
- CVE-2026-81994: Adobe Acrobat Reader prototype pollution arbitrary file readhighCVSS 8.2EPSS 0.6%
- CVE-2026-81993: Adobe Acrobat Reader heap buffer overflow in PDF parsingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-81992: Adobe Acrobat Reader heap-based buffer overflowhighCVSS 7.8EPSS 0.3%
- CVE-2026-81991: Adobe Acrobat Reader out-of-bounds read in memory parsingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-81990: Adobe Acrobat Reader use-after-free remote code executionhighCVSS 7.8EPSS 0.4%
- CVE-2026-81989: Adobe Acrobat Reader use-after-free in parsinghighCVSS 7.8EPSS 0.4%
- CVE-2026-81988: Adobe Acrobat Reader use-after-freehighCVSS 7.8EPSS 0.4%
- CVE-2026-81987: Adobe Acrobat Reader integer overflow in PDF parsinghighCVSS 7.8EPSS 0.3%
- CVE-2026-81986: Adobe Acrobat Reader use-after-free in PDF handlinghighCVSS 7.8EPSS 0.4%
- CVE-2026-81985: Adobe Acrobat Reader use-after-freehighCVSS 7.8EPSS 0.4%
- CVE-2026-81984: Adobe Acrobat Reader use after free in memory handlingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-81983: Adobe Acrobat Reader out-of-bounds write vulnerabilityhighCVSS 7.8EPSS 0.3%
- CVE-2026-81982: Adobe Acrobat Reader out-of-bounds read in PDF parsingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-81981: Adobe Acrobat Reader out-of-bounds writehighCVSS 7.8EPSS 0.3%
- CVE-2026-81980: Adobe Acrobat Reader out-of-bounds write in PDF parsinghighCVSS 7.8EPSS 0.3%
- CVE-2026-81979: Adobe Acrobat Reader out-of-bounds write arbitrary code executionhighCVSS 7.8EPSS 0.3%
- CVE-2026-81978: Adobe Acrobat Reader out-of-bounds read in PDF parsingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-81977: Adobe Acrobat Reader integer underflow in memory handlingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-81976: Adobe Acrobat Reader use-after-freehighCVSS 7.8EPSS 0.4%
- CVE-2026-81975: Adobe Acrobat Reader use-after-free vulnerabilityhighCVSS 7.8EPSS 0.4%
- CVE-2026-81973: Adobe Acrobat Reader use-after-free vulnerabilityhighCVSS 7.8EPSS 0.4%
- CVE-2026-80162: Adobe Acrobat Reader use-after-free in memory handlingmediumCVSS 5.5EPSS 0.3%
- CVE-2026-80161: Adobe Acrobat Reader type confusion vulnerabilityhighCVSS 7.8EPSS 0.3%
Most severe Adobe Acrobat vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2008-4250: Microsoft Windows buffer overflow in Server servicecriticalexploited in the wildCVSS 10EPSS 93.5%
- CVE-2011-2462: Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2014-0546: Adobe Reader and Acrobat Sandbox Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2013-2729: Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2013-3346: Adobe Reader and Acrobat Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2009-3459: Adobe Acrobat and Reader heap overflow in PDF parsingcriticalexploited in the wildCVSS 9.3EPSS 87.0%
- CVE-2009-4324: Adobe Acrobat and Reader Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 9.3
- CVE-2009-1862: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerabilitycriticalexploited in the wildCVSS 9.3
- CVE-2011-0609: Adobe Flash Player Unspecified Vulnerabilitycriticalexploited in the wildCVSS 9.3
- CVE-2010-1297: Adobe Flash Player Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 31 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/acrobat.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Adobe Acrobat vulnerabilities", https://junglewise.ai/threats/technologies/acrobat, 26 September 2026.