Adobe patches two critical vulnerabilities in Acrobat and Reader

Adobe has released a security update fixing two critical vulnerabilities in Adobe Acrobat and Reader for Windows and macOS. CVE-2026-27220 and CVE-2026-27278, both with a CVSS score of 7.8, could allow arbitrary code execution. Adobe states it has not observed exploitation of either flaw in the wild.

What this means for your business

PDF is the format your organisation receives from people it does not know: quotes, invoices, applications and attachments. Code execution through a PDF reader gives an attacker a foothold on an ordinary office machine with that employee's access. That exploitation has not been observed yet simply means you have a little time. The details are now public.

Berigo recommends

  • Roll out the Adobe update to all clients, and verify coverage rather than trusting that automation caught everyone.
  • Check for Acrobat or Reader installations on servers and in case management systems, which often fall outside client patching.
  • Enable protected view in the PDF reader for documents originating outside the organisation.
  • Set a deadline in your patching routine for critical flaws in software that processes external files.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch