CVE-2016-0940: Adobe Acrobat

Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0932, CVE-2016-0934, CVE-2016-0937, and CVE-2016-0941.

Affected products

  • Adobe Acrobat: up to and including 11.0.13; version 11.0.0 only; version 11.0.1 only; version 11.0.2 only; version 11.0.3 only; version 11.0.4 only; …
  • Adobe Acrobat DC: up to and including 15.006.30097; up to and including 15.009.20077
  • Adobe Acrobat Reader: up to and including 11.0.13; version 11.0.0 only; version 11.0.1 only; version 11.0.2 only; version 11.0.3 only; version 11.0.4 only; …
  • Adobe Acrobat Reader DC: up to and including 15.006.30097; up to and including 15.009.20077

Published 2016-01-14. Last modified 2026-06-17.