Adobe
Adobe Acrobat: vulnerabilities and CVEs
Adobe Acrobat has 1,414 published vulnerabilities, 65 of them in the last 12 months. 219 are rated critical and 24 are listed by CISA as actively exploited.
CVEs1,414
Last 12 months65
Critical219
Actively exploited24
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3459 | High (8.8) | 87% | ⚠ Active exploitation | Oct 13, 2009 | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as… |
| CVE-2026-34621 | High (8.6) | 2.2% | ⚠ Active exploitation | Apr 11, 2026 | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary… |
| CVE-2023-21608 | High (7.8) | 61% | ⚠ Active exploitation | Jan 18, 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the… |
| CVE-2023-26369 | High (7.8) | 6.7% | ⚠ Active exploitation | Sep 13, 2023 | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the… |
| CVE-2008-0655 | High (8.8) | 38% | ⚠ Active exploitation | Feb 7, 2008 | Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. |
| CVE-2010-2883 | High (7.3) | 81% | ⚠ Active exploitation | Sep 9, 2010 | Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service… |
| CVE-2009-1862 | High (7.8) | 21% | ⚠ Active exploitation | Jul 23, 2009 | Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of… |
| CVE-2009-4324 | High (7.8) | 82% | ⚠ Active exploitation | Dec 15, 2009 | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code… |
| CVE-2010-1297 | High (7.8) | 83% | ⚠ Active exploitation | Jun 8, 2010 | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to… |
| CVE-2009-3953 | High (8.8) | 83% | ⚠ Active exploitation | Jan 13, 2010 | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document,… |
| CVE-2011-2462 | Critical (9.8) | 89% | ⚠ Active exploitation | Dec 7, 2011 | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or… |
| CVE-2011-0609 | High (7.8) | 64% | ⚠ Active exploitation | Mar 15, 2011 | Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka… |
| CVE-2007-5659 | High (7.8) | 87% | ⚠ Active exploitation | Feb 12, 2008 | Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be… |
| CVE-2014-0546 | Critical (9.8) | 22% | ⚠ Active exploitation | Aug 12, 2014 | Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified… |
| CVE-2013-2729 | Critical (9.8) | 67% | ⚠ Active exploitation | May 16, 2013 | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727. |
| CVE-2008-2992 | High (7.8) | 98% | ⚠ Active exploitation | Nov 4, 2008 | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string… |
| CVE-2011-0611 | High (8.8) | 99% | ⚠ Active exploitation | Apr 13, 2011 | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before… |
| CVE-2014-0496 | High (8.8) | 40% | ⚠ Active exploitation | Jan 15, 2014 | Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors. |
| CVE-2013-0640 | High (7.8) | 87% | ⚠ Active exploitation | Feb 14, 2013 | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as… |
| CVE-2013-0641 | High (7.8) | 32% | ⚠ Active exploitation | Feb 14, 2013 | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82001 | Medium (5.5) | 0.23% | — | Sep 8, 2026 | Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in… |
| CVE-2026-81997 | Medium (6.3) | 0.24% | — | Sep 8, 2026 | Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized… |
| CVE-2026-81996 | High (8.8) | 0.24% | — | Sep 8, 2026 | Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this… |
| CVE-2026-81994 | Medium (6.3) | 0.60% | — | Sep 8, 2026 | Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this… |
| CVE-2026-81993 | Medium (5.5) | 0.30% | — | Sep 8, 2026 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation… |
| CVE-2026-81992 | High (7.8) | 0.34% | — | Sep 8, 2026 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… |
| CVE-2026-81991 | Medium (5.5) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this… |
| CVE-2026-81990 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81989 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81988 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81987 | High (7.8) | 0.31% | — | Sep 8, 2026 | Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in… |
| CVE-2026-81986 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81985 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81984 | Medium (5.5) | 0.33% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue… |
| CVE-2026-81983 | High (7.8) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim… |
| CVE-2026-81982 | Medium (5.5) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this… |
| CVE-2026-81981 | High (7.8) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim… |
| CVE-2026-81980 | High (7.8) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim… |
| CVE-2026-81979 | High (7.8) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim… |
| CVE-2026-81978 | Medium (5.5) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this… |
| CVE-2026-81977 | Medium (5.5) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information.… |
| CVE-2026-81976 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81975 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-81973 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |
| CVE-2026-80162 | Medium (5.5) | 0.33% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue… |
| CVE-2026-80161 | High (7.8) | 0.29% | — | Sep 8, 2026 | Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit… |
| CVE-2026-80160 | Medium (5.5) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this… |
| CVE-2026-80159 | Medium (4) | 0.19% | — | Sep 8, 2026 | Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends… |
| CVE-2026-79910 | Medium (5.5) | 0.26% | — | Sep 8, 2026 | Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this… |
| CVE-2026-79909 | High (7.8) | 0.38% | — | Sep 8, 2026 | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… |