CVE-2026-47924

Summary

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Software

VendorProductVersion RangeStatus
AdobeAcrobat DC0 <= 26.001.21651affected
AdobeAcrobat DC26.001.21662unaffected
AdobeAcrobat Reader DC0 <= 26.001.21651affected
AdobeAcrobat Reader DC26.001.21662unaffected
AdobeAcrobat 20240 <= 24.001.30365affected
AdobeAcrobat 202424.001.30383unaffected

Weaknesses

  • CWE-416: Use After Free (CWE-416)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References