FAIL › dossier
Acrobat and Reader
PRODUCT· dossier confidence 40%
Adobe Inc. is a public technology company focused on digital media and content creation, but faces significant security risks due to repeated critical RCE vulnerabilities in Acrobat and Reader products.
PROFILE
CategorySoftware VendorWhat they doAdobe Inc. operates as a technology company worldwide, with the Digital Media segment offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content.Ownershippublic
Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE
High-risk track record with repeated critical RCE vulnerabilities in Acrobat and Reader, including prototype pollution and heap-based buffer overflows.
Notable failures
- CVE-2026-34621: Prototype pollution RCE in Acrobat/Reader
- CVE-2009-3459: Heap-based buffer overflow RCE in Acrobat/Reader
- CVE-2026-48282: ColdFusion path traversal RCE
Patterns: Repeated critical RCE vulnerabilities in PDF products; High-severity vulnerabilities in Adobe ColdFusion
FAILURE HISTORY · 13
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-03 | CVE-2008-2992 | critical | A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution. |
| 2026-04-13 | CVE-2026-34621 | high | Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution. |
| 2022-06-08 | CVE-2007-5659 | high | A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files. |
| 2021-11-03 | CVE-2021-21017 | high | Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild. |
| 2021-11-03 | CVE-2021-28550 | high | Adobe Acrobat and Reader suffered a use-after-free vulnerability allowing unauthenticated remote code execution. |
| 2023-10-10 | CVE-2023-21608 | high | Adobe Acrobat and Reader Use-After-Free Vulnerability |
| 2023-09-14 | CVE-2023-26369 | high | Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution. |
| 2022-06-08 | CVE-2009-3953 | high | A vulnerability in Adobe Acrobat and Reader allowed attackers to execute code remotely via malicious 3D files, actively exploited in the wild and impacting DIB organizations reliant on these tools for document handling. |
| 2022-06-08 | CVE-2008-0655 | high | A design flaw in Adobe Acrobat and Reader allowed silent, arbitrary printing of specially crafted files, marking it as an actively exploited vulnerability. |
| 2022-06-08 | CVE-2010-2883 | high | A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products. |
| 2022-06-08 | CVE-2018-4990 | high | A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products. |
| 2026-05-20 | CVE-2009-3459 | high | Adobe Acrobat and Reader exploited a heap-based buffer overflow vulnerability allowing remote code execution via crafted PDF files. |
| 2022-06-08 | CVE-2009-4324 | high | A crafted PDF file can trigger remote code execution in Adobe Acrobat and Reader due to a use-after-free vulnerability, actively exploited in the wild. |
DOSSIER SOURCES
- Adobe (ADBE) Company Profile & Description - Stock Analysis · stockanalysis.com
- Adobe System Status · status.adobe.com
- Adobe Release Notes - June 2026 Latest Updates - Releasebot · releasebot.io
- ColdFusion CVE-2026-48282 exploited: 3-day KEV deadline, patch to ... · lilting.ch
Open questions: Adobe's remediation timeline for CVE-2026-34621 · Impact of CVE-2026-34621 on CMMC compliance
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 04:00:15.853535+00:00