Adobe Acrobat and Reader: 46 records in one advisory
46 records announced together, published 2018-07-09, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb18-09.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
1 record is listed by CISA with a required action, which carries a federal remediation deadline on its own page.
6 of 46 records name something of its own. For the other 40, held sources say the same thing about each.
Most commonly mapped weakness across the batch: Out-of-bounds read.
What this page does not cover
This batch is 46 of the 48 records that cite the same advisory. The other 2 are different findings announced alongside it.
None of those 2 is grouped with any other. Each one has its own record page and nothing else.
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Most of this May 2018 Reader batch came from researchers; one came out of a live attack
Adobe published this bulletin for Acrobat and Reader on 14 May 2018. One entry in it did not come from anyone hunting bugs. CVE-2018-4990 was found by Anton Cherepanov of ESET and Matt Oh of Microsoft while they were examining a malicious PDF file pulled from a public malware repository. The sample chained a Reader flaw to a Windows privilege escalation flaw, CVE-2018-8120, so that opening the document was enough to take the machine. Microsoft published the analysis on 2 July 2018. Adobe's bulletin records that an exploit for CVE-2018-4990 existed in the wild, and the United States cyber defence agency added that identifier on 8 June 2022 to its catalogue of vulnerabilities known to have been exploited. Nothing comparable is on record for any other identifier in this group.
One of these, CVE-2018-4990, turned up in a real attack before there was a fix. Sharing a bulletin with it tells you nothing about whether any other record here was ever used against anybody.
Adobe gives a flaw class and an impact for each identifier and no technical detail, so nothing says which file feature or code path is involved in any one of them. The dates do not line up either: Adobe's bulletin is dated 14 May 2018 while the records in this group carry a publication date of 9 July 2018, and no source we can link explains the gap.
Written from helpx.adobe.com, microsoft.com, securityweek.com, cisa.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
46 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.