CVE-2026-47965: Acrobat Reader | Out-of-bounds Write (CWE-787)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Adobe Acrobat Readerfrom your environment.Where Acrobat Reader is not required, uninstall it from affected systems to eliminate exposure to the described vulnerability.
- Compensating control
Identify endpoints running Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. Until a vendor fix is applied, block or strip PDF attachments from untrusted external email at the gateway and/or prevent users from opening PDFs from untrusted sources to reduce likelihood of exploitation (the vulnerability requires a user to open a malicious file).
- Operational
Inform and train users to not open PDF files from unknown or untrusted senders and to treat unexpected PDF attachments as potentially malicious. If a user opens a suspicious PDF, isolate the affected system and follow incident response procedures.
- Operational
Monitor Adobe security advisories and apply vendor-supplied updates or patches for Acrobat Reader as soon as they are published (no fixed version is specified in the provided material).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47965?
The severity of CVE-2026-47965 is rated high with a score of 7.8.
How do I fix CVE-2026-47965?
To fix CVE-2026-47965, update Adobe Acrobat Reader to version 24.001.30366, 26.001.21652, or later.
What type of vulnerability is CVE-2026-47965?
CVE-2026-47965 is an out-of-bounds write vulnerability.
What is the risk associated with CVE-2026-47965?
The risk associated with CVE-2026-47965 includes arbitrary code execution in the context of the current user.
What is required for exploitation of CVE-2026-47965?
Exploitation of CVE-2026-47965 requires user interaction, specifically the victim must open a malicious file.