CVE-2026-27221: Adobe Acrobat
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
Affected products
- Adobe Acrobat: from 24.001.20604, before 24.001.30356 (fixed in 24.001.30356)
- Adobe Acrobat DC: before 25.001.21288 (fixed in 25.001.21288)
- Adobe Acrobat Reader DC: before 25.001.21288 (fixed in 25.001.21288)
Published 2026-03-10. Last modified 2026-08-28.