Acrobat

Vendor:

First CVE: Oct 20, 2000 · Active for 25 years

1,381
Total CVEs
More Total CVEs than 100% of tracked products
57.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
1.7%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Acrobat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Jun 16, 2026
38 days ago

CVE Severity & Scoring

Acrobat1,381 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local489 (35.4%)
Network439 (31.8%)
Unknown453 (32.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low924 (66.9%)
High4 (0.3%)
Unknown453 (32.8%)
User Interaction
None237 (17.2%)
Unknown453 (32.8%)
Required691 (50.0%)
Privileges Required
Low12 (0.9%)
High0 (0.0%)
None916 (66.3%)
Unknown453 (32.8%)

Top CVEs

Signals from CVEs in this product scope (1381 CVEs).

1,381 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote att
Dec 7, 20119.898YESYES
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib
Apr 13, 20118.898YESYES
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute ar
Feb 22, 20107.898YESYES
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript fun
Nov 4, 20087.898YESYES
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) vi
Aug 30, 20139.897YESYES
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary c
Sep 9, 20107.397YESYES
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac
Jun 8, 20107.897YESYES
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code vi
Jan 13, 20108.897YESYES
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remo
Dec 15, 20097.897YESYES
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF fi
Oct 13, 20098.897YESYES

Exploit Exposure

Signals from CVEs in this product scope (1381 CVEs).

CISA KEV
24 CVEs
1.7% of CVEs· 96th percentile
Metasploit
16 CVEs
1.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
43 CVEs
3.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (1381 CVEs).

Media Mentions

Signals from CVEs in this product scope (1381 CVEs).

Top CNAs Publishing CVEs For Acrobat

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.5.4249.88.2%01
9.5.3249.88.2%01
9.5.2529.87.6%01
9.5.1739.88.5%01
9.5769.88.6%01
9.4.7809.78.8%01
9.4.6819.88.3%01
9.4.5899.88.0%01
9.4.41019.67.8%01
9.4.31029.67.8%01
9.4.21029.67.8%01
9.4.11309.58.5%01
9.41329.39.4%03
9.3.41539.48.7%04
9.3.31559.29.2%05
9.3.21699.48.6%07
9.3.11839.38.5%07
9.31839.48.7%07
9.21859.38.4%07
9.1.31949.38.6%08