The current version of Adobe Acrobat Reader is 26.002.21996 (as of 06/10/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
7.8 high · locally only, without login, needs user action · CISA deadline was 24 Mar 22
7.8 high · locally only, with a basic account · CISA deadline was 24 Mar 22
- CVE-2013-3346Adobe Reader and Acrobat Memory Corruption Vulnerability
9.8 critical · over the network, without login · CISA deadline was 24 Mar 22
- CVE-2013-2729Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability
9.8 critical · over the network, without login · CISA deadline was 18 Apr 22
- CVE-2014-0546Adobe Reader and Acrobat Sandbox Bypass Vulnerability
9.8 critical · over the network, without login · CISA deadline was 15 Jun 22
- CVE-2011-2462Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
9.8 critical · over the network, without login · CISA deadline was 22 Jun 22
- CVE-2021-28550Adobe Acrobat and Reader Use-After-Free Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2021-21017Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2014-0496Adobe Reader and Acrobat Use-After-Free Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 24 Mar 22
- CVE-2009-0927Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 15 Apr 22
- CVE-2008-0655Adobe Acrobat and Reader Unspecified Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 22 Jun 22
- CVE-2009-3953Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 22 Jun 22
- CVE-2018-4990Adobe Acrobat and Reader Double Free Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 22 Jun 22
- CVE-2009-3459Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 3 Jun
- CVE-2026-34621Adobe Acrobat and Reader Prototype Pollution Vulnerability
8.6 high · locally only, without login, needs user action · CISA deadline was 27 Apr
- CVE-2013-0640Adobe Reader and Acrobat Memory Corruption Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 24 Mar 22
- CVE-2007-5659Adobe Acrobat and Reader Buffer Overflow Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 22 Jun 22
- CVE-2009-1862Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 22 Jun 22
- CVE-2009-4324Adobe Acrobat and Reader Use-After-Free Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 22 Jun 22
- CVE-2023-26369Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 5 Oct 23
- CVE-2023-21608Adobe Acrobat and Reader Use-After-Free Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 31 Oct 23
- CVE-2010-2883Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
7.3 high · locally only, with a basic account, needs user action · CISA deadline was 22 Jun 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Adobe Acrobat und Acrobat Reader: Mehrere Schwachstellen
WID-SEC-W-2026-3249 · 11 Sept
- Adobe Acrobat und Adobe Acrobat Reader: Mehrere Schwachstellen
WID-SEC-W-2026-1862 · 20 Jul
- Adobe Acrobat und Acrobat Reader: Mehrere Schwachstellen
WID-SEC-W-2026-1068 · 24 Jun
Adobe Acrobat Reader at a glance
Adobe Acrobat and Reader open PDF documents — files that routinely arrive from untrusted sources, which makes the PDF parser a well-worn attack vector. Adobe ships regular security updates (typically on Patch Tuesday) plus out-of-band fixes for actively exploited flaws.
For admins prompt patching is the point: PDF-handling vulnerabilities have been exploited in the wild, so keep Acrobat/Reader current across the fleet. Roll updates via the Adobe enterprise tooling, winget or the MSI; source only from Adobe. Restrict risky features (JavaScript in PDFs) via the admin controls where policy allows, and prefer the Protected Mode/sandbox. Older, unpatched Reader installs on shared machines are the classic weak spot — enforce a minimum version.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 2020 Classic (Acrobat Reader 2020) | – | End of Life |
| 2017 Classic (Acrobat Reader 2017) | – | End of Life |
| 2015 Classic (Acrobat Reader DC 2015) | – | End of Life |
| XI (11.x) | – | End of Life |
| X (10.x) | – | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 26.002.21996 | STABLE | 06/10/2026 | Release notes → |
| 26.002.21931 | STABLE | 18/09/2026 | Release notes → |
| 26.002.21901 | STABLE | 09/09/2026 | Release notes → |
| 26.002.21900 | STABLE | 08/09/2026 | Release notes → |
| 26.002.21869 | STABLE | 29/08/2026 | Release notes → |
| 26.001.21789 | STABLE | 12/08/2026 | Release notes → |
| 26.001.21771 | STABLE | 01/08/2026 | Release notes → |
| 26.001.21745 | STABLE | 24/07/2026 | Release notes → |
| 26.001.21691 | STABLE | 08/07/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Adobe Acrobat Reader?
- Adobe Acrobat Reader 26.002.21996, released 06/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Adobe Acrobat Reader release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Adobe Acrobat Reader updates?
- Tick Adobe Acrobat Reader off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Adobe Acrobat Reader version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Adobe Acrobat Reader version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/adobe-acrobat-reader)https://patchletter.com/badge/adobe-acrobat-reader.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).