Adobe Acrobat and Reader: 86 records in one advisory
86 records announced together, published between 2019-01-18 and 2019-01-28, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb18-41.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.
Most commonly mapped weakness across the batch: Out-of-bounds read.
What this page does not cover
Every record citing this advisory is on this page.
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Adobe's December 2018 Acrobat release, and the 86 records that followed it five weeks later
SecurityWeek reported that Adobe's December 2018 Acrobat and Reader update closed 87 vulnerabilities across the Continuous and Classic 2015 tracks and Acrobat 2017. It lists the organisations Adobe credited: Tencent, Source Incite, NSFocus, Beihang University, Trend Micro, the Chinese Academy of Sciences, Baidu, Qihoo 360, Ruhr University Bochum, Cisco Talos, Zero Day Initiative, Palo Alto Networks, Knownsec 404 and independent researchers. That is more than a dozen separate teams whose work happened to be ready for the same release. SecurityWeek also reports Adobe saying it had no indication that any of them had been exploited. The records themselves did not appear when the update did. Our index holds 86 records naming this bulletin, published between 18 January and 28 January 2019, five weeks after the update and spread across ten days.
These are separate faults in one document reader, found by teams competing against each other and by paid reporting programmes, and collected into one scheduled release. Installing the update is one action, but each record stands on its own and none of them describes the others.
SecurityWeek lists the organisations Adobe credited but does not say which identifier belongs to which organisation, and Adobe's own acknowledgements table is not readable to us, so no record in this group can be matched to its reporter. There is also a count that does not line up: the release is reported as 87 vulnerabilities and we hold 86 records naming it, and no source we can read accounts for the missing one.
Written from securityweek.com, tenable.com, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
86 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.