CVE-2026-47911: Acrobat Reader | Out-of-bounds Write (CWE-787)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Acrobat Readerfrom your environment.Uninstall Acrobat Reader from systems where it is not required to eliminate exposure to the vulnerability.
- Compensating control
Block or scan PDF attachments at the email gateway and endpoint (anti-malware/secure email gateway) and restrict opening PDFs from untrusted sources to reduce the risk of a user opening a malicious file.
- Operational
Advise and train users not to open unexpected or untrusted PDF files, since exploitation requires user interaction (opening a malicious file).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47911?
The severity of CVE-2026-47911 is rated high with a score of 7.8.
How do I fix CVE-2026-47911?
To fix CVE-2026-47911, you should update Adobe Acrobat Reader to the latest version provided by Adobe.
What impact does CVE-2026-47911 have on my system?
CVE-2026-47911 can allow arbitrary code execution in the context of the current user if a malicious file is opened.
Which versions of Adobe Acrobat Reader are affected by CVE-2026-47911?
CVE-2026-47911 affects Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier.
Is user interaction required to exploit CVE-2026-47911?
Yes, user interaction is required as the victim must open a malicious file for CVE-2026-47911 to be exploited.