CVE-2026-47924: Acrobat Reader | Use After Free (CWE-416)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Because exploitation requires a victim to open a malicious file, restrict or isolate handling of PDF files from untrusted sources until a vendor fix is applied. Examples: block or quarantine PDF attachments from unknown senders at mail gateway, require opening untrusted PDFs only in sandboxed/isolated virtual machines or dedicated document-viewer sandboxes, and enforce user awareness to not open suspicious PDFs.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47924?
CVE-2026-47924 has a medium severity rating of 5.5.
How do I fix CVE-2026-47924?
To fix CVE-2026-47924, users should update Adobe Acrobat Reader to the latest version.
What type of vulnerability is CVE-2026-47924?
CVE-2026-47924 is classified as a Use After Free vulnerability (CWE-416).
What could happen if CVE-2026-47924 is exploited?
If CVE-2026-47924 is exploited, it could lead to the disclosure of sensitive memory information.
What versions of Adobe Acrobat Reader are affected by CVE-2026-47924?
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier are affected by CVE-2026-47924.