Adobe Acrobat Reader Remote Code Execution Vulnerability CVE-2026-1047
Summary
CERT-Bund issued a critical security advisory for Adobe Acrobat Reader vulnerability CVE-2026-1047 with CVSS Base Score of 9.6. The flaw allows remote, unauthenticated attackers to execute arbitrary code and gain full administrative control of affected systems running Windows, UNIX, and other operating systems. Adobe Acrobat Reader versions up to and including 26.001.21367 are affected.
What changed
CERT-Bund published a critical security advisory identifying a remote code execution vulnerability in Adobe Acrobat Reader affecting versions up to 26.001.21367. The vulnerability allows an unauthenticated remote attacker to disclose confidential information and execute arbitrary code, potentially achieving full system compromise with administrative privileges.
Organizations using Adobe Acrobat Reader on Windows, UNIX, or other platforms must prioritize immediate patching to the latest secure version. Security teams should implement defense-in-depth controls including email/web filtering for PDF attachments, network segmentation, and continuous monitoring for exploitation attempts. Failure to remediate exposes systems to remote takeover and data exfiltration risks.
What to do next
- Apply Adobe security patches for Acrobat Reader immediately
- Implement network-level controls to block malicious PDF delivery
- Monitor for indicators of exploitation and apply workarounds if patches unavailable
Archived snapshot
Apr 10, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
[WID-SEC-2026-1047] Adobe Acrobat Reader: Schwachstelle ermöglicht Erlangen von Administratorrechten CVSS Base Score 9.6 (kritisch) CVSS Temporal Score 9.6 (kritisch) Remoteangriff ja Datum 09.04.2026 Stand 10.04.2026 Mitigation nein
Betroffene Systeme
Betriebssystem
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
Adobe Reader ist ein Programm für die Anzeige von Dokumenten im Portable Document Format (PDF).
Produkte
09.04.2026
- Adobe Acrobat Reader <=26.001.21367
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Adobe Acrobat Reader ausnutzen, um vertrauliche Informationen offenzulegen und beliebigen Code auszuführen, was zu einer vollständigen Kompromittierung des Systems führen könnte. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Get daily alerts for CERT-Bund Security Advisories
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.