CVE-2026-47913: Acrobat Reader | Use After Free (CWE-416)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block, strip, or sandbox PDF attachments at email gateways and web proxies to prevent users from opening potentially malicious files.
- Compensating control
Isolate viewing of untrusted PDFs (for example, require opening in a VM, container, or other sandboxed/restricted environment) and enforce least-privilege for accounts that run Acrobat Reader.
- Compensating control
Instruct users not to open PDF files from untrusted or unexpected sources and provide targeted awareness/training about this vulnerability class (malicious files requiring user interaction).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47913?
The severity of CVE-2026-47913 is rated as high with a CVSS score of 7.8.
What software versions are affected by CVE-2026-47913?
CVE-2026-47913 affects Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier.
How do I fix CVE-2026-47913?
To fix CVE-2026-47913, update Adobe Acrobat Reader to the latest version provided by Adobe.
What type of vulnerability is CVE-2026-47913?
CVE-2026-47913 is a Use After Free vulnerability that could lead to arbitrary code execution.
What is required for exploitation of CVE-2026-47913?
Exploitation of CVE-2026-47913 requires user interaction, as the victim must open a malicious file.