CVE-2026-47926: Acrobat Reader | Out-of-bounds Read (CWE-125)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not open PDF files from untrusted or unknown sources — exploitation requires a victim to open a malicious file.
- Compensating control
Block, quarantine, or sandbox PDF attachments at email gateways and perimeter security tools and scan PDFs with antivirus/behavioral analysis before delivery to users.
- Operational
Inform and train users to report and not open unsolicited or unexpected PDF files; instruct security team to treat reported PDFs as potentially malicious until analyzed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47926?
The severity of CVE-2026-47926 is rated medium with a CVSS score of 5.5.
How do I fix CVE-2026-47926?
To fix CVE-2026-47926, users should update their Adobe Acrobat Reader to the latest version available.
What types of systems are affected by CVE-2026-47926?
CVE-2026-47926 affects Adobe Acrobat Reader, Adobe Acrobat DC, and Adobe Acrobat Reader DC versions 24.001.30365, 26.001.21651, and earlier.
What is the nature of the vulnerability in CVE-2026-47926?
CVE-2026-47926 is an out-of-bounds read vulnerability that may allow for the disclosure of sensitive memory.
What is required for exploitation of CVE-2026-47926?
Exploitation of CVE-2026-47926 requires user interaction.