CVE-2026-47924

MEDIUM

Acrobat Reader | Use After Free (CWE-416)

Title source: cna
STIX 2.1

Description

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 15.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (4)
adobe/acrobat 24.0.0 - 24.001.30383
Adobe/Acrobat Reader < 26.001.21651
adobe/acrobat_dc 15.008.20082 - 26.001.21662
adobe/acrobat_reader_dc 15.008.20082 - 26.001.21662
Published Jun 09, 2026
Tracked Since Jun 10, 2026