VDB

CVE-2023-26369

CVE-2023-26369 PUBLISHED KEV CVSS 7.800000190734863 HIGH

Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses a critical vulnerability. Successful exploitation could lead to arbitrary code execution . Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader. Vulnerability: Out-of-bounds Write (CWE-787) Impact: Arbitrary code execution Severity: Critical CVSS: 7.8 CWE: CWE-787

EPSS 7.06% · 93.8th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
7.06%
93.8th percentile

Affected Products

VendorProductVersions
AdobeAcrobat Reader DC23.003.20284, 23.003.20284, 23.003.20284
AdobeAcrobat DC23.003.20284, 23.003.20284, 23.003.20284
AdobeAcrobat Reader 202020.005.30516, 20.005.30516, 20.005.30516
AdobeAcrobat 202020.005.30516, 20.005.30516, 20.005.30516

Timeline

  • Sep 12, 2023 CVE Published
  • Sep 12, 2023 VulnCheck KEV Exploitation
  • Sep 12, 2023 PoC Published
  • Sep 13, 2023 VulnCheck KEV Exploitation
  • Sep 13, 2023 EPSS Score
  • Sep 13, 2023 PoC Published
  • Sep 14, 2023 CISA KEV Added
  • Sep 14, 2023 VulnCheck KEV Exploitation
  • Sep 14, 2023 PoC Published
  • Sep 16, 2023 EPSS Score
  • Sep 18, 2023 EPSS Score
  • Oct 17, 2023 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›