CVE-2026-27221: Adobe Acrobat

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.

Affected products

  • Adobe Acrobat: from 24.001.20604, before 24.001.30356 (fixed in 24.001.30356)
  • Adobe Acrobat DC: before 25.001.21288 (fixed in 25.001.21288)
  • Adobe Acrobat Reader DC: before 25.001.21288 (fixed in 25.001.21288)

Published 2026-03-10. Last modified 2026-08-28.