← Vulnerability feed

Vulnerability record · CVE-2023-26369 · published 13 September 2023

CVE-2023-26369: Adobe Acrobat and Reader out-of-bounds write allows code execution

Adobe · Acrobat

Adobe Acrobat and Reader versions 23.003.20284, 20.005.30516 and 20.005.30514 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue in a widely deployed document reader.

7.8 CVSS 3.1 High CISA KEV since 14 Sep 2023 EPSS 6.7% · top 6.3% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
6.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows code execution in a widely used client, is listed in CISA KEV as exploited in the wild, and has a high EPSS percentile, though it requires user interaction.

What it is

Adobe Acrobat and Reader versions 23.003.20284, 20.005.30516 and 20.005.30514 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue in a widely deployed document reader.

Impact

An attacker who gets a victim to open a crafted file can execute arbitrary code with the privileges of the current user. That enables malware installation, data theft or further compromise of the user's system.

Attack surface

Reached locally through a malicious file opened in Acrobat or Reader; the CVSS vector shows AV:L, PR:N and UI:R, so no authentication is needed but user interaction (opening the file) is required.

Exploitation

CVE-2023-26369 was added to CISA KEV on 2023-09-14, indicating known exploitation in the wild; EPSS 30-day probability is about 7.1% (93.9th percentile). No ransomware campaign use is documented in the record.

What to do

  • Apply the Adobe security update for APSB23-34 to Acrobat, Acrobat DC, Acrobat Reader and Acrobat Reader DC as soon as possible.
  • If patching cannot be completed immediately, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
  • Enforce automatic updates for Acrobat and Reader and verify installed versions are above the affected builds.
  • Restrict or block untrusted PDF and document attachments at email and web gateways where feasible.
  • Educate users not to open unexpected or unsolicited PDF files from unknown senders.

Detection

  • Hunt for Acrobat or Reader processes spawning child processes such as cmd.exe, powershell.exe or scripting hosts, which is abnormal for normal PDF viewing.
  • Monitor for document files written to temp or user directories followed by execution of dropped binaries.
  • Review endpoint telemetry for crashes or memory corruption events in Acrobat/Reader that may indicate exploitation attempts.
  • Check email and web proxy logs for PDF attachments or downloads from untrusted sources delivered to users running affected versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-26369 to the Known Exploited Vulnerabilities catalog on 14 September 2023 as "Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 October 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26369 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2018-4990Adobe Acrobat and Reader double free allows code executionAdobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and e…KEVEPSS 36%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed

Source: NIST National Vulnerability Database (record CVE-2023-26369), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.