[UPDATE] [medium] Adobe Acrobat and Adobe Acrobat Reader: Multiple Vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Adobe Acrobat and Adobe Acrobat Reader to execute arbitrary code, disclose sensitive information, or cause a denial-of-service.
CSIRTS triage
- What
- A remote, anonymous attacker can exploit multiple vulnerabilities in Adobe Acrobat and Adobe Acrobat Reader to execute arbitrary code, disclose sensitive information, or cause a denial-of-service.
- Who is affected
- Users of Adobe Acrobat and Adobe Acrobat Reader are affected.
- Urgency
- Remediation is medium urgency as multiple vulnerabilities exist, but exploitation is not currently active.
- Action
- Update to the latest versions of Adobe Acrobat and Adobe Acrobat Reader.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Adobe Acrobat and Adobe Acrobat Reader
Get an email when a new Adobe Acrobat and Adobe Acrobat Reader advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1862
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-479650.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
- Low exploitation riskCVE-2026-483730.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-479110.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-479120.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-479130.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-479140.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-479150.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-479160.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-479170.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-479180.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Adobe Acrobat and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownSecurity Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-63)jpcert · 2026-06-10
- criticalexploitedCVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerabilitycisa-kev · 2026-05-20
- unknownSecurity Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)jpcert · 2026-04-15
- criticalexploitedCVE-2020-9715: Adobe Acrobat Use-After-Free Vulnerabilitycisa-kev · 2026-04-13
- criticalexploitedCVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerabilitycisa-kev · 2026-04-13
- criticalexploitedCVE-2023-21608: Adobe Acrobat and Reader Use-After-Free Vulnerabilitycisa-kev · 2023-10-10
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31