.

Adobe Security Bulletin

Last updated on Jun 15, 2026

Security update available for Adobe Acrobat Reader | APSB26-63

Bulletin ID
Date Published
Priority
APSB26-63
June 9, 2026
2

Summary

Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution, application denial-of-service, and memory exposure.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.

Affected Versions

Product
Track
Affected Versions
Platform
Adobe Acrobat
Continuous
26.001.21651 and earlier
Windows & macOS
Acrobat Reader
Continuous
26.001.21651 and earlier
Windows & macOS
Acrobat 2024
Classic 2024
24.001.30365 and earlier
Windows & macOS

For questions regarding Adobe Acrobat, please visit the Adobe Acrobat FAQ page.

For questions regarding Acrobat Reader, please visit the Acrobat Reader FAQ page.

Solution

Adobe recommends users update their software installations to the latest versions by following the instructions below.

The latest product versions are available to end users via one of the following methods:

  • Users can update their product installations manually by choosing Help > Check for Updates.
  • The products will update automatically, without requiring user intervention, when updates are detected.
  • The full Acrobat Reader installer can be downloaded from the Acrobat Reader Download Center.

For IT administrators (managed environments):

  • Refer to the specific release note version for links to installers.
  • Install updates via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM (Windows), or on macOS, Apple Remote Desktop and SSH.

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:

Product
Track
Updated Versions
Platform
Priority Rating
Availability
Adobe Acrobat
Continuous
26.001.21662
Windows and macOS
2
Acrobat Reader
Continuous
26.001.21662
Windows and macOS
2
Acrobat 2024
Classic 2024
24.001.30383
Windows and macOS
2

Vulnerability Details

Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVE Number
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47911
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47965
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47912
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47913
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47914
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47915
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47916
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47917
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47918
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47919
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47920
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47921
Use After Free (CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47955
Stack-based Buffer Overflow (CWE-121)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47959
Heap-based Buffer Overflow (CWE-122)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47952
Uncontrolled Search Path Element (CWE-427)
Arbitrary code execution
Critical
7.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
CVE-2026-47937
Out-of-bounds Read (CWE-125)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-47961
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-47923
Use After Free (CWE-416)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-47924
Integer Overflow or Wraparound (CWE-190)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2026-47925
Out-of-bounds Read (CWE-125)
Memory exposure
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-47926

Acknowledgements

Adobe would like to thank the following researchers for reporting these issues and for working with Adobe to help protect our customers:

  • Seiji Sakurai (@HeapSmasher) working with TrendAI Zero Day Initiative - CVE-2026-47911
  • Mark Vincent Yason (markyason.github.io) working with TrendAI Zero Day Initiative - CVE-2026-47912, CVE-2026-47913, CVE-2026-47923, CVE-2026-47924
  • Brandon Evans of TrendAI Zero Day Initiative - CVE-2026-47915
  • Tao Yan (@Ga1ois) and Edouard Bochin (@le_douds) of Palo Alto Networks - CVE-2026-47916
  • Dongeui Ko (d0c70r) - CVE-2026-47925
  • Yu Zhou and Yutao Wang of YunShangHuaAn (yutao_wang) - CVE-2026-47926, CVE-2026-47959
  • Anonymous working with TrendAI Zero Day Initiative - CVE-2026-47914
  • Anonymous working with TrendAI Zero Day Initiative - CVE-2026-47917
  • Anonymous working with TrendAI Zero Day Initiative - CVE-2026-47918
  • XP - CVE-2026-47920, CVE-2026-47921, CVE-2026-47961, CVE-2026-47955
  • Anonymous - CVE-2026-47952
  • Pedro J. Nunez-Cacho Fuentes (@tunelko) - CVE-2026-47937
  • NoE9ybCAT (qtuvteqhlv) - CVE-2026-47965

Revisions

  • June 10, 2026 - Updated download center link.
  • June 12, 2026 - Added CVE-2026-47965.
  • June 15, 2026 - Updated researcher credit for CVE-2026-47952.