CVE-2023-26369: Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2023-09-14. EPSS: 6.7% chance of exploitation in the next 30 days.
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected products
- Adobe Acrobat: from 20.001.3005, before 20.005.30524 (fixed in 20.005.30524)
- Adobe Acrobat DC: from 15.007.20033, before 23.006.20320 (fixed in 23.006.20320)
- Adobe Acrobat Reader: from 20.001.3005, before 20.005.30524 (fixed in 20.005.30524)
- Adobe Acrobat Reader DC: from 15.007.20033, before 23.006.20320 (fixed in 23.006.20320)
Published 2023-09-13. Last modified 2026-06-17.