CVE-2026-79907 Details
Description
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
A double free vulnerability has been identified in Adobe Acrobat and Acrobat Reader. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file. The issue affects Adobe Acrobat and Acrobat Reader versions through 26.002.21900, as well as Acrobat 2024 versions through 24.001.30383, on both Windows and macOS.
Users are advised to update to the latest versions of Adobe Acrobat or Acrobat Reader. The latest versions can be downloaded from the Adobe website or via the Adobe Update mechanism. For IT administrators, updates are available through various deployment methods, including SCUP/SCCM on Windows or Apple Remote Desktop and SSH on macOS.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb26-141.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-415 | Double Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe acrobat | >= 24.001.20604, < 24.001.30429 |
CPE
Remediation
| |
| adobe acrobat dc | >= 15.008.20082, < 26.002.21901 |
CPE
Remediation
| |
| adobe acrobat reader dc | >= 15.008.20082, < 26.002.21901 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | Initial Analysis | [email protected] |
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |