CVE-2026-47952: Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Adobe Acrobat Readerfrom your environment.Uninstall Adobe Acrobat Reader from systems where it is not required to eliminate exposure to the reported heap-based buffer overflow.
- Compensating control
Mitigate risk from required user interaction by preventing or isolating untrusted PDF files: block or sandbox PDF attachments at email and web gateways, apply content-scanning/antivirus on incoming PDFs, and restrict users from opening unsolicited or untrusted PDF files. Use isolated or virtualized environments for opening PDFs when necessary.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47952?
The severity of CVE-2026-47952 is classified as high with a base score of 7.8.
How do I fix CVE-2026-47952?
To fix CVE-2026-47952, update Adobe Acrobat Reader to the latest version that addresses this vulnerability.
What does CVE-2026-47952 exploit?
CVE-2026-47952 exploits a heap-based buffer overflow vulnerability that can lead to arbitrary code execution.
Which versions of Adobe Acrobat Reader are affected by CVE-2026-47952?
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by CVE-2026-47952.
What is required for the exploitation of CVE-2026-47952?
Exploitation of CVE-2026-47952 requires user interaction, specifically that a victim must open a malicious file.