.

Adobe Security Bulletin

Last updated on Sep 8, 2026

Security update available for Adobe Acrobat Reader  | APSB26-141

Bulletin ID
Date published
Priority
APSB26-141
September 8, 2026
2

Summary

Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses critical, important, and moderate vulnerabilities that could result in arbitrary code execution, privilege escalation, arbitrary file system read, arbitrary file system write, memory exposure, and application denial-of-service.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Affected Versions

Product

Track
Affected Versions
Platform
Adobe Acrobat
Continuous
26.002.21900 and earlier
Windows &  macOS
Acrobat Reader
Continuous
26.002.21900 and earlier
Windows & macOS
Acrobat 2024
Classic 2024
24.001.30383 and earlier
Windows & macOS

Solution

Adobe recommends users update their software installations to the latest versions by following the instructions below.

The latest product versions are available to end users via one of the following methods:

For IT administrators (managed environments):

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:

Product
Track
Updated versions
Platform
Priority rating
Availability
Adobe Acrobat
Continuous
26.002.21901
Windows and macOS
2
Acrobat Reader
Continuous
26.002.21901
Windows and macOS
2
Acrobat 2024
Classic 2024
24.001.30429
Windows and macOS
2

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Incorrect Authorization (CWE-863)
Privilege escalation
Critical
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-81996
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Arbitrary file system read
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-81994
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81983
Double Free (CWE-415)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-79907
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-79908
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-79909
Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-80161
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81973
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81975
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81976
Heap-based Buffer Overflow (CWE-122)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81992
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81979
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81980
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81981
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81985
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81986
Integer Overflow or Wraparound (CWE-190)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81987
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81988
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81989
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-81990
Incorrect Authorization (CWE-863)
Arbitrary file system write
Important
6.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVE-2026-81997
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-81982
Uncontrolled Resource Consumption (CWE-400)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2026-82001
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-80160
Use After Free (CWE-416)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-80162
Integer Underflow (Wrap or Wraparound) (CWE-191)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-81977
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-81978
Heap-based Buffer Overflow (CWE-122)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-81993
Use After Free (CWE-416)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-81984
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-81991
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-79910
Untrusted Search Path (CWE-426)
Privilege escalation
Critical
4.0
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
CVE-2026-80159

Acknowledgements

Adobe would like to thank the following researchers for reporting these issues and for working with Adobe to help protect our customers:

  • Andrea Intilangelo — CVE-2026-80159
  • OmriD-Remedio (omrid) — CVE-2026-81983, CVE-2026-81982
  • Jony (jony_juice) — CVE-2026-79907, CVE-2026-79908
  • Mark Vincent Yason (markyason.github.io) working with Trend Micro Zero Day Initiative — CVE-2026-80161, CVE-2026-81973, CVE-2026-81990, CVE-2026-79909
  • Anonymous working with Trend Micro Zero Day Initiative — CVE-2026-81975, CVE-2026-81976, CVE-2026-81981, CVE-2026-81985, CVE-2026-81986, CVE-2026-81988, CVE-2026-81989, CVE-2026-81977, CVE-2026-81984, CVE-2026-81991
  • Ame (raincandy_u) — CVE-2026-81979
  • NoE9ybCAT (qtuvteqhlv) — CVE-2026-81980
  • Brandon Evans of Trend Micro Zero Day Initiative — CVE-2026-81987
  • NURIHAN KIM (HanTul) working with Trend Micro Zero Day Initiative — CVE-2026-80160, CVE-2026-80162, CVE-2026-81978
  • Kiwan Ko working with TrendAI Zero Day Initiative — CVE-2026-79910

Revisions:

  • June 10, 2026 - Updated download center link.
  • June 12, 2026 - Added CVE-2026-47965.
  • June 15, 2026 - Updated researcher credit for CVE-2026-47952.
  • July 17, 2026 - Added CVE-2026-48373.