[NEU] [hoch] Adobe Acrobat und Acrobat Reader: Mehrere Schwachstellen
Ein lokaler Angreifer kann mehrere Schwachstellen in Adobe Acrobat und Adobe Acrobat Reader ausnutzen, um beliebigen Code auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3249
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-799070.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-799080.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-799090.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-799100.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-801590.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-801600.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-801610.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-801620.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819730.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819750.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans les produits Adobe (09 septembre 2026)cert-fr-avis
- mediumCVE-2026-82001: Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could le…nvd
- mediumCVE-2026-81997: Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-81996: Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- highCVE-2026-81994: Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attrib…nvd
- mediumCVE-2026-81993: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to di…nvd
- highCVE-2026-81992: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in …nvd
- mediumCVE-2026-81991: Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosur…nvd
- highCVE-2026-81990: Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary co…nvd
- highCVE-2026-81989: Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary co…nvd
- highCVE-2026-81988: Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary co…nvd
- highCVE-2026-81987: Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could resul…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10