CVE-2026-47923: Acrobat Reader | Out-of-bounds Read (CWE-125)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acrobat Readerto a version that resolves this vulnerability.Fixed in 24.001.30365 - Upgrade
Upgrade
Acrobat Readerto a version that resolves this vulnerability.Fixed in 26.001.21651 - Compensating control
Mitigate user-interaction requirement by ensuring users do not open untrusted/malicious files (e.g., treat unsolicited attachments as untrusted)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47923?
The severity of CVE-2026-47923 is medium, with a score of 5.5.
How do I fix CVE-2026-47923?
To fix CVE-2026-47923, update Adobe Acrobat Reader to the latest version released after June 9, 2026.
What type of vulnerability is CVE-2026-47923?
CVE-2026-47923 is categorized as an out-of-bounds read vulnerability.
What could be the impact of exploiting CVE-2026-47923?
Exploiting CVE-2026-47923 could lead to the disclosure of sensitive memory information.
Does CVE-2026-47923 require user interaction for exploitation?
Yes, exploitation of CVE-2026-47923 requires user interaction.