CVE-2026-27278Disclosure(adobe / acrobat)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe acrobat systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_dc
  • acrobat_reader_dc
  • macos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
acrobatacrobat_dcacrobat_reader_dcmacoswindows

1 version affected across 5 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-04-10: 1Active Exploitation · 2026-04-10: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-1003-1104-10
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-111
Disclosure1
2026-04-101
Active Exploitation1
Full discourse3 posts
  • dbugs@ptdbugs
    Disclosure

    Acrobat Reader | Use After Free (CWE-416) CVE: CVE-2026-27278 Vendor: Adobe Product: Acrobat Reader CVSS: 7.8 Credits: n/a Description: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27278 • https://helpx.adobe.com/security/products/acrobat/apsb26-26.html #dbugs_vuln

    Post summary

    The post announces a Use After Free vulnerability in Acrobat Reader with technical details and references a vendor patch.

    0000257
    556 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-27278 in Adobe Reader through malicious PDFs targeting Russian oil and gas sectors. Post-compromise lateral movement demonstrates how document exploits can escalate into network-wide breaches. Runtime segmentation helps contain such breach chains. #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/adobe-reader-zero-day-exploit-december-2025

    Post summary

    The tweet reports that attackers are actively exploiting CVE‑2026‑27278 via malicious PDFs targeting Russian oil and gas sectors, indicating real-world exploitation but providing no technical or remediation details.

    0000069
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27278 Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execut… https://www.cve.org/CVERecord?id=CVE-2026-27278

    Post summary

    The notice announces Adobe Acrobat Reader’s Use‑After‑Free vulnerability (CVE‑2026‑27278), detailing affected versions and the risk of arbitrary code execution, but offers no PoC, exploit, or patch information.

    0000096
    56.7K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat_dc---
Appadobeacrobat_reader_dc---
OSapplemacos---
OSmicrosoftwindows---

Explore more