Skip to content
Weekly Signal
Demonstration intelligence Updated 17 Aug 2026 · 18:42 UTC

Adobe · Acrobat

CVE-2026-31704

Memory safety flaw requiring user interaction

Recommended action

Include the update in the normal desktop patch cycle and continue monitoring for exploitation evidence.

View response plan
CVSS9.8
EPSS0.4%
KEVNo
ExploitationNo known exploitation
PatchAvailable

Assessment

Why it matters

The theoretical impact is high, but exploitation probability is very low and there is no KEV or active-exploitation evidence.

Who should care

  • Endpoint management teams
  • Desktop security teams
  • Risk owners tracking document-borne threats

Response plan

What I would do

  1. Confirm the product is in scope.
  2. Deploy through the normal patch ring.
  3. Keep protected mode controls enabled.
  4. Maintain email and web filtering.
  5. Reprioritise if threat evidence changes.

Technical details

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-416: Use After Free
Affected versions
Demonstration range: selected Acrobat and Reader releases
Published
16 Aug 2026
Attack vector
Network
Privileges required
None
User interaction
Required

Signal timeline

  1. Advisory published
  2. Initial scoring added
  3. EPSS remains below 1%
  4. Signal remains 31
Demonstration data This page shows the intended product experience using fictional CVE records. Dates, evidence, affected versions and recommendations must not be used as live security advice.