---
id: CVE-2026-81993
title: >-
  Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that
  could lead to disclosure of sensitive memory
summary: >-
  Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that
  could lead to disclosure of sensitive memory. An attacker could leverage this
  vulnerability to disclose sensitive information. Exploitation of this issue
  requi…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-122
vendor: adobe
product: acrobat
affected:
  - 'acrobat >= 24.001.20604, < 24.001.30429'
  - 'acrobat_dc >= 15.008.20082, < 26.002.21901'
  - 'acrobat_reader_dc >= 15.008.20082, < 26.002.21901'
patched:
  - acrobat 24.001.30429
  - acrobat_dc 26.002.21901
  - acrobat_reader_dc 26.002.21901
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:26:55.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81993'
references:
  - url: 'https://helpx.adobe.com/security/products/acrobat/apsb26-141.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
epss: 0.003
epssPercentile: 0.20217
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T13:50:27.013790Z'
ingestedAt: '2026-09-08T21:11:12.369Z'
---

## Overview

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `acrobat >= 24.001.20604, < 24.001.30429`
- `acrobat_dc >= 15.008.20082, < 26.002.21901`
- `acrobat_reader_dc >= 15.008.20082, < 26.002.21901`

## Remediation

Upgrade past the affected range:

- `acrobat 24.001.30429`
- `acrobat_dc 26.002.21901`
- `acrobat_reader_dc 26.002.21901`
