CVE-2026-27220: Acrobat Reader | Use After Free (CWE-416)
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27220?
CVE-2026-27220 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2026-27220?
To fix CVE-2026-27220, update Adobe Acrobat Reader to the latest version available beyond 25.001.21265.
What versions of Adobe Acrobat Reader are affected by CVE-2026-27220?
CVE-2026-27220 affects Adobe Acrobat Reader versions 24.001.30307, 24.001.30308, and versions up to but not including 25.001.21265.
What does CVE-2026-27220 exploit require for successful execution?
Exploitation of CVE-2026-27220 requires user interaction to succeed.
What is a Use After Free vulnerability like CVE-2026-27220?
A Use After Free vulnerability, such as CVE-2026-27220, occurs when a program continues to use a pointer after the memory it points to has been freed, potentially leading to arbitrary code execution.