CVE-2019-8237: Adobe Acrobat DC
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an insufficiently robust encryption vulnerability. Successful exploitation could lead to security feature bypass.
Affected products
- Adobe Acrobat DC: from 15.006.30060, before 15.006.30499 (fixed in 15.006.30499); from 15.008.20082, before 19.012.20036 (fixed in 19.012.20036); from 17.011.30059, before 17.011.30144 (fixed in 17.011.30144)
- Adobe Acrobat Reader DC: from 15.006.30060, before 15.006.30499 (fixed in 15.006.30499); from 15.008.20082, before 19.012.20036 (fixed in 19.012.20036); from 17.011.30059, before 17.011.30144 (fixed in 17.011.30144)
Published 2019-10-23. Last modified 2026-06-17.