CVE-2026-47919: Acrobat Reader | Use After Free (CWE-416)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or filter PDF attachments from untrusted sources at email and web gateways and restrict opening of untrusted PDFs, since exploitation requires a victim to open a malicious file.
- Operational
Inventory installed Acrobat Reader instances and identify any installations at versions 24.001.30365, 26.001.21651 or earlier.
- Operational
Advise users not to open unexpected or untrusted PDF files and instruct them to report suspicious files to IT for analysis.
- Operational
Monitor Adobe security advisories and apply vendor-provided Acrobat Reader updates/patches as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47919?
The severity of CVE-2026-47919 is high with a score of 7.8.
What is CVE-2026-47919?
CVE-2026-47919 is a Use After Free vulnerability in Adobe Acrobat Reader that could allow for arbitrary code execution.
How do I fix CVE-2026-47919?
To fix CVE-2026-47919, update Adobe Acrobat Reader to the latest version provided by Adobe.
What are the affected versions for CVE-2026-47919?
Affected versions for CVE-2026-47919 include Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier.
What exploitation conditions are required for CVE-2026-47919?
Exploitation of CVE-2026-47919 requires user interaction as the victim must open a malicious file.