Adobe fixes nearly 140 flaws, two critical ones in Acrobat and Reader
On 9 and 10 December 2025 Adobe published a broad security release covering nearly 140 vulnerabilities. Bulletin APSB25-119 details four flaws in Acrobat and Reader for Windows and macOS, two of them critical, allowing arbitrary code execution through untrusted search paths and out-of-bounds reads. Two moderate issues make it possible to bypass cryptographic signature checks. The release also covers ColdFusion, Experience Manager with 117 issues, the DNG SDK and Creative Cloud Desktop. No exploitation in the wild has been reported.
What this means for your organisation
Acrobat and Reader sit on practically every endpoint, and PDF is the format organisations accept from outside without a second thought: invoices, quotes, applications and attachments from unknown senders. The signature bypass deserves separate attention wherever signed PDFs serve as documentation in contracts or audits, because it touches trust in the document rather than just the machine. Experience Manager and ColdFusion are often internet-facing and belong in the same round.
Berigo recommends
- Deploy the Acrobat and Reader update through your endpoint platform and verify coverage, not merely that the job ran.
- Put ColdFusion and Experience Manager first in the queue if they are internet-facing.
- Review where the business relies on signed PDFs as evidence, and check whether that trust rests on client-side validation.
- Set a fixed deadline for critical endpoint patches, for instance seven days, and report exceptions to management.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch