CVE-2013-0640: Adobe Reader and Acrobat Memory Corruption Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
CSIRTS triage
- What
- A memory corruption vulnerability in Adobe Reader allows an attacker to perform remote code execution.
- Who is affected
- Users of Adobe Reader and Acrobat are affected by this vulnerability.
- Urgency
- Remediation is urgent due to active exploitation and critical severity.
- Action
- Update to the latest version of Adobe Reader and Acrobat.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Reader and Acrobat
Get an email when a new Reader and Acrobat advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2013-0640
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2013-0640Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2013-0640 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Adobe Reader and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [medium] Adobe Acrobat and Adobe Acrobat Reader: Multiple Vulnerabilitiescert-bund · 2026-07-20
- unknownSecurity Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-63)jpcert · 2026-06-10
- criticalexploitedCVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerabilitycisa-kev · 2026-05-20
- unknownSecurity Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)jpcert · 2026-04-15
- criticalexploitedCVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerabilitycisa-kev · 2026-04-13
- criticalexploitedCVE-2023-21608: Adobe Acrobat and Reader Use-After-Free Vulnerabilitycisa-kev · 2023-10-10
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-60004: Gitea Code Injection Vulnerability2026-08-25
- criticalCVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerabil…2026-08-24
- criticalCVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability2026-08-21
- criticalCVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability2026-08-20
- criticalCVE-2026-72530: TrueConf Server Code Injection Vulnerability2026-08-20