CVE-2026-47914: Acrobat Reader | Use After Free (CWE-416)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Prevent or limit users from opening untrusted PDF files: block or quarantine PDF attachments at the email gateway and web proxy, and disable automatic PDF preview in email clients and webmail.
- Compensating control
Require that PDF attachments from unknown or untrusted sources be scanned and analyzed (antivirus/sandbox) before being opened, or be opened only in an isolated sandbox/VM environment.
- Compensating control
Educate users that exploitation requires opening a malicious file and instruct them not to open unexpected or suspicious PDFs; report such files to security for analysis.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47914?
CVE-2026-47914 has a high severity rating of 7.8.
How do I fix CVE-2026-47914?
To fix CVE-2026-47914, update Adobe Acrobat Reader to the latest version provided by Adobe.
What systems are affected by CVE-2026-47914?
CVE-2026-47914 affects Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier.
What type of vulnerability is CVE-2026-47914?
CVE-2026-47914 is classified as a Use After Free vulnerability, categorized under CWE-416.
What is the impact of exploiting CVE-2026-47914?
Exploitation of CVE-2026-47914 can lead to arbitrary code execution in the context of the current user.