CVE-2026-47921: Acrobat Reader | Use After Free (CWE-416)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Exploit requires a user to open a malicious file. Reduce exposure by preventing users from opening PDFs from untrusted sources: block or scan incoming PDF attachments at email/web gateways, restrict or warn on opening PDFs from untrusted locations, and educate users not to open unexpected PDF files.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47921?
CVE-2026-47921 has a severity rating of high, with a score of 7.8.
What software is affected by CVE-2026-47921?
CVE-2026-47921 affects Adobe Acrobat Reader versions 24.001.30365 and 26.001.21651 and earlier.
What is the risk associated with CVE-2026-47921?
CVE-2026-47921 carries a risk score of 68, indicating significant potential harm if exploited.
How do I fix CVE-2026-47921?
To fix CVE-2026-47921, users should update to the latest version of Adobe Acrobat Reader or Adobe Acrobat DC.
What type of vulnerability is CVE-2026-47921?
CVE-2026-47921 is classified as a Use After Free vulnerability, which can lead to arbitrary code execution.