Skip to content
COOEY

FAIL › dossier

Acrobat and Reader

PRODUCT

· dossier confidence 40%

Adobe Inc. is a public technology company focused on digital media and content creation, but faces significant security risks due to repeated critical RCE vulnerabilities in Acrobat and Reader products.

PROFILE
CategorySoftware VendorWhat they doAdobe Inc. operates as a technology company worldwide, with the Digital Media segment offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content.Ownershippublic Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE

High-risk track record with repeated critical RCE vulnerabilities in Acrobat and Reader, including prototype pollution and heap-based buffer overflows.

Notable failures
  • CVE-2026-34621: Prototype pollution RCE in Acrobat/Reader
  • CVE-2009-3459: Heap-based buffer overflow RCE in Acrobat/Reader
  • CVE-2026-48282: ColdFusion path traversal RCE
Patterns: Repeated critical RCE vulnerabilities in PDF products; High-severity vulnerabilities in Adobe ColdFusion
FAILURE HISTORY · 13
DATEEVENTSEVSUMMARY
2022-03-03 CVE-2008-2992 critical A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution.
2026-04-13 CVE-2026-34621 high Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.
2022-06-08 CVE-2007-5659 high A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files.
2021-11-03 CVE-2021-21017 high Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild.
2021-11-03 CVE-2021-28550 high Adobe Acrobat and Reader suffered a use-after-free vulnerability allowing unauthenticated remote code execution.
2023-10-10 CVE-2023-21608 high Adobe Acrobat and Reader Use-After-Free Vulnerability
2023-09-14 CVE-2023-26369 high Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution.
2022-06-08 CVE-2009-3953 high A vulnerability in Adobe Acrobat and Reader allowed attackers to execute code remotely via malicious 3D files, actively exploited in the wild and impacting DIB organizations reliant on these tools for document handling.
2022-06-08 CVE-2008-0655 high A design flaw in Adobe Acrobat and Reader allowed silent, arbitrary printing of specially crafted files, marking it as an actively exploited vulnerability.
2022-06-08 CVE-2010-2883 high A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products.
2022-06-08 CVE-2018-4990 high A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.
2026-05-20 CVE-2009-3459 high Adobe Acrobat and Reader exploited a heap-based buffer overflow vulnerability allowing remote code execution via crafted PDF files.
2022-06-08 CVE-2009-4324 high A crafted PDF file can trigger remote code execution in Adobe Acrobat and Reader due to a use-after-free vulnerability, actively exploited in the wild.
Open questions: Adobe's remediation timeline for CVE-2026-34621 · Impact of CVE-2026-34621 on CMMC compliance
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 04:00:15.853535+00:00