Assessment
Why it matters
The theoretical impact is high, but exploitation probability is very low and there is no KEV or active-exploitation evidence.
Who should care
- Endpoint management teams
- Desktop security teams
- Risk owners tracking document-borne threats
Response plan
What I would do
- Confirm the product is in scope.
- Deploy through the normal patch ring.
- Keep protected mode controls enabled.
- Maintain email and web filtering.
- Reprioritise if threat evidence changes.
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-416: Use After Free
- Affected versions
- Demonstration range: selected Acrobat and Reader releases
- Published
- 16 Aug 2026
- Attack vector
- Network
- Privileges required
- None
- User interaction
- Required
Signal timeline
- Advisory published
- Initial scoring added
- EPSS remains below 1%
- Signal remains 31