CVE-2026-79907
massDouble Free Vulnerability in Adobe Acrobat Reader Allows Arbitrary Code Execution
Adobe Acrobat Reader contains a Double Free memory corruption flaw (CWE-415) in which the same memory allocation is freed twice, corrupting heap state. The bug is triggered locally when a victim opens a maliciously crafted file, most plausibly a crafted PDF, so successful attacks require user interaction. An attacker who exploits it gains arbitrary code execution in the context of the current user, meaning malware runs with the privileges of the logged-in account rather than the system. Anyone running Adobe Acrobat Reader is potentially affected; the available data does not specify the affected version ranges or fixed builds, so defenders should check the Adobe security bulletin for details. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, indicating no evidence of exploitation yet.
What to do: Install the latest Acrobat Reader update issued by Adobe for CVE-2026-79907 as soon as your environment allows, and check the Adobe PSIRT advisory for the exact affected and fixed builds since no version numbers are provided here. Until patching is complete, warn users not to open PDFs from untrusted or unexpected sources and ensure Acrobat's Protected Mode/Enhanced Security features remain enabled. Because there is no known PoC or in-the-wild exploitation, routine patch-cadence handling is appropriate, but watch the Adobe advisory for updated version details.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.