CVE-2016-6938: Adobe Acrobat

Critical severity, CVSS 9.8. EPSS: 8.7% chance of exploitation in the next 30 days.

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4255.

Affected products

  • Adobe Acrobat: up to and including 11.0.16
  • Adobe Acrobat DC: up to and including 15.006.30174; up to and including 15.016.20045
  • Adobe Acrobat Reader DC: up to and including 15.006.30174; up to and including 15.016.20045
  • Adobe Reader: up to and including 11.0.16

Published 2016-09-17. Last modified 2026-06-17.