All CVEs
Vulnerability intelligence

CVE-2026-48294

Adobe Adobe Acrobat PDF Extension (Chrome) CWE-79

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVSS Score
7.4
High
EPSS — Exploit Probability
1.9%
Riskier than 78% of all CVEs · checked 2026-09-05
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

3 articles across 3 outlets · first covered Jul 22, 2026 · latest Jul 23, 2026

Coverage timeline

Related CVEs — Adobe