CVE-2023-26369: Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2023-09-14. EPSS: 6.7% chance of exploitation in the next 30 days.

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected products

  • Adobe Acrobat: from 20.001.3005, before 20.005.30524 (fixed in 20.005.30524)
  • Adobe Acrobat DC: from 15.007.20033, before 23.006.20320 (fixed in 23.006.20320)
  • Adobe Acrobat Reader: from 20.001.3005, before 20.005.30524 (fixed in 20.005.30524)
  • Adobe Acrobat Reader DC: from 15.007.20033, before 23.006.20320 (fixed in 23.006.20320)

Published 2023-09-13. Last modified 2026-06-17.