Adobe Acrobat Dc vulnerabilities

1,779 known vulnerabilities affecting adobe/acrobat_dc.

Total CVEs
1,779
CISA KEV
7
actively exploited
Public exploits
25
Exploited in wild
5
Severity breakdown
CRITICAL449HIGH847MEDIUM451LOW32

Vulnerabilities

Page 1 of 89
CVE-2026-34621HIGHCVSS 8.6KEVfixed in 26.001.214112026-04-11
CVE-2026-34621 [HIGH] CWE-1321 CVE-2026-34621: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Control Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma
nvd
CVE-2026-27220HIGHCVSS 7.8fixed in 25.001.212882026-03-10
CVE-2026-27220 [HIGH] CWE-416 CVE-2026-27220: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use A Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-27278HIGHCVSS 7.8fixed in 25.001.212882026-03-10
CVE-2026-27278 [HIGH] CWE-416 CVE-2026-27278: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use A Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-27221MEDIUMCVSS 5.5fixed in 25.001.212882026-03-10
CVE-2026-27221 [MEDIUM] CWE-295 CVE-2026-27221: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Impr Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
nvd
CVE-2025-64899HIGHCVSS 7.8fixed in 25.001.209972025-12-09
CVE-2025-64899 [HIGH] CWE-125 CVE-2025-64899: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current
nvd
CVE-2025-64785HIGHCVSS 8.4fixed in 25.001.209972025-12-09
CVE-2025-64785 [HIGH] CWE-426 CVE-2025-64785: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could m
nvd
CVE-2025-64787MEDIUMCVSS 4.0fixed in 25.001.209972025-12-09
CVE-2025-64787 [MEDIUM] CWE-347 CVE-2025-64787: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass cryptographic protections and gain limited unauthorized writ
nvd
CVE-2025-64786MEDIUMCVSS 4.0fixed in 25.001.209972025-12-09
CVE-2025-64786 [MEDIUM] CWE-347 CVE-2025-64786: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue
nvd
CVE-2025-54257HIGHCVSS 7.8≥ 15.008.20082, < 25.001.206932025-09-09
CVE-2025-54257 [HIGH] CWE-416 CVE-2025-54257: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use A Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.
nvd
CVE-2025-54255MEDIUMCVSS 4.0≥ 15.008.20082, < 25.001.206932025-09-09
CVE-2025-54255 [MEDIUM] CWE-657 CVE-2025-54255: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Viola Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.
nvd
CVE-2025-43576HIGHCVSS 7.8≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43576 [HIGH] CWE-416 CVE-2025-43576: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43575HIGHCVSS 7.8≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43575 [HIGH] CWE-787 CVE-2025-43575: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out- Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43574HIGHCVSS 7.8≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43574 [HIGH] CWE-416 CVE-2025-43574: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43577HIGHCVSS 7.8≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43577 [HIGH] CWE-416 CVE-2025-43577: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43573HIGHCVSS 7.8≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43573 [HIGH] CWE-416 CVE-2025-43573: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43550HIGHCVSS 7.8≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43550 [HIGH] CWE-416 CVE-2025-43550: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-47112MEDIUMCVSS 5.5fixed in 25.001.20531fixed in 25.001.205292025-06-10
CVE-2025-47112 [MEDIUM] CWE-125 CVE-2025-47112: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out- Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicio
nvd
CVE-2025-43578MEDIUMCVSS 5.5≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43578 [MEDIUM] CWE-125 CVE-2025-43578: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out- Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicio
nvd
CVE-2025-47111MEDIUMCVSS 5.5fixed in 25.001.20531fixed in 25.001.205292025-06-10
CVE-2025-47111 [MEDIUM] CWE-476 CVE-2025-47111: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a v
nvd
CVE-2025-43579MEDIUMCVSS 5.5≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43579 [MEDIUM] CWE-200 CVE-2025-43579: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Info Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
nvd
1 / 89Next →