Skip to main content
Participant
July 9, 2026
Question

Requesting patch deployment details to remediate high-severity vulnerability CVE-2026-45447 on endpoint currently running Adobe Acrobat Reader version 2026.001.21691.

  • July 9, 2026
  • 2 replies
  • 71 views

My endpoint security scanner is alerting on a high-severity heap use-after-free vulnerability, CVE-2026-45447, stemming from the embedded OpenSSL cryptographic library (PKCS7_verify() function) inside Adobe Acrobat. Our endpoint currently has Adobe Acrobat Reader Continuous Release (Version 2026.001.21691, 64-bit) installed. According to Adobe Security Bulletin APSB26-63, this update timeline addresses critical flaws, but we require verification on whether this build completely resolves the specific OpenSSL flaw, or if an additional out-of-band update is required. Please provide the exact target patch version alongside any command-line parameters needed to safely push the update across our environment.

    2 replies

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 13, 2026

    Hello ​@Harry 

     

    Hope you well, and sorry for the delayed response.

     

    We are currently evaluating the required OpenSSL update. As part of this effort, the reported vulnerability is expected to be addressed in a future release after completing the necessary validation and regression testing.

    We are targeting the earliest available release and will share the release details here on the thread once the update has been finalized. 

     

    Thanks for your cooperation.

    Regards,

    Anand Sri.

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 9, 2026

    Hello ​@Harry 

    I hope you are doing well, and we are sorry for the trouble.

     

    I will get this checked internally and will get back to you with an update.

     

    Regards,

    Anand Sri.