Adobe Acrobat Reader vulnerabilities
1,105 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,105
CISA KEV
21
actively exploited
Public exploits
43
Exploited in wild
25
Severity breakdown
CRITICAL352HIGH411MEDIUM315LOW27
Vulnerabilities
Page 1 of 56
CVE-2026-34621HIGHCVSS 8.6KEV≤ 26.001.213672026-04-11
CVE-2026-34621 [CRITICAL] CWE-1321 CVE-2026-34621: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Control
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open
cvelistv5nvd
CVE-2026-27220HIGHCVSS 7.8≤ 25.001.212652026-03-10
CVE-2026-27220 [HIGH] CWE-416 CVE-2026-27220: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2026-27278HIGHCVSS 7.8≤ 25.001.212652026-03-10
CVE-2026-27278 [HIGH] CWE-416 CVE-2026-27278: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2026-27221MEDIUMCVSS 5.5≤ 25.001.212652026-03-10
CVE-2026-27221 [MEDIUM] CWE-295 CVE-2026-27221: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Impr
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
cvelistv5nvd
CVE-2025-64899HIGHCVSS 7.8≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64899 [HIGH] CWE-125 CVE-2025-64899: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current
cvelistv5nvd
CVE-2025-64785HIGHCVSS 8.4≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64785 [HIGH] CWE-426 CVE-2025-64785: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could m
cvelistv5nvd
CVE-2025-64787MEDIUMCVSS 4.0≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64787 [LOW] CWE-347 CVE-2025-64787: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass cryptographic protections and gain limited unauthorized write a
cvelistv5nvd
CVE-2025-64786MEDIUMCVSS 4.0≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64786 [LOW] CWE-347 CVE-2025-64786: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue doe
cvelistv5nvd
CVE-2025-54257HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30791≤ 25.001.206722025-09-09
CVE-2025-54257 [HIGH] CWE-416 CVE-2025-54257: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.
cvelistv5nvd
CVE-2025-54255MEDIUMCVSS 4.0≥ 20.001.30002, < 20.005.30791≤ 25.001.206722025-09-09
CVE-2025-54255 [MEDIUM] CWE-657 CVE-2025-54255: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Viola
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.
cvelistv5nvd
CVE-2025-43576HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43576 [HIGH] CWE-416 CVE-2025-43576: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2025-43575HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43575 [HIGH] CWE-787 CVE-2025-43575: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2025-43577HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43577 [HIGH] CWE-416 CVE-2025-43577: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2025-43573HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43573 [HIGH] CWE-416 CVE-2025-43573: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2025-43550HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43550 [HIGH] CWE-416 CVE-2025-43550: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2025-43574HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43574 [HIGH] CWE-416 CVE-2025-43574: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2025-47112MEDIUMCVSS 5.5≥ 20.0, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-47112 [MEDIUM] CWE-125 CVE-2025-47112: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicio
cvelistv5nvd
CVE-2025-43578MEDIUMCVSS 5.5≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43578 [MEDIUM] CWE-125 CVE-2025-43578: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicio
cvelistv5nvd
CVE-2025-47111MEDIUMCVSS 5.5≥ 20.0, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-47111 [MEDIUM] CWE-476 CVE-2025-47111: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a v
cvelistv5nvd
CVE-2025-43579MEDIUMCVSS 5.5≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43579 [MEDIUM] CWE-200 CVE-2025-43579: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Info
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
cvelistv5nvd
1 / 56Next →