CVE-2026-27221: Acrobat Reader | Improper Certificate Validation (CWE-295)
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27221?
CVE-2026-27221 is rated as a high-severity vulnerability due to its potential to bypass security features.
How do I fix CVE-2026-27221?
To fix CVE-2026-27221, users should upgrade to the latest version of Adobe Acrobat Reader that addresses this vulnerability.
What versions are affected by CVE-2026-27221?
CVE-2026-27221 affects Adobe Acrobat Reader versions up to and including 25.001.21265.
What type of vulnerability is CVE-2026-27221?
CVE-2026-27221 is classified as an Improper Certificate Validation vulnerability.
Can CVE-2026-27221 be exploited remotely?
Yes, an attacker could exploit CVE-2026-27221 remotely to bypass security features in affected versions of Adobe Acrobat Reader.