ZeroHour

CVE-2026-79908

mass

Out-of-Bounds Write in Adobe Acrobat Reader Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p7
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains an out-of-bounds write vulnerability (CWE-787), a memory corruption flaw in which the application writes data past the boundaries of an allocated buffer. The flaw is triggered when a victim opens a maliciously crafted file, most plausibly a PDF, meaning the attack requires user interaction rather than being remotely exploitable on its own. An attacker who successfully exploits it gains the ability to run arbitrary code in the context of the current user, with that user's privileges rather than elevated system rights. Anyone running the affected builds of Acrobat Reader is potentially exposed, and because the reader is opened on countless endpoints daily, malicious-file delivery via email or web download is the realistic attack path. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and its EPSS score of 0.2% (7th percentile) suggests a low near-term probability of exploitation.

What to do: Update Acrobat Reader to the latest release per Adobe's advisory for CVE-2026-79908, since the source data does not list fixed version numbers. As interim mitigations, avoid opening PDFs from untrusted or unexpected sources, ensure the current user runs without administrative rights on endpoints, and verify that email gateways and endpoint security are inspecting PDF attachments. Defenders should treat this as high severity given code execution impact, while noting no known exploitation yet.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is one of the most widely installed desktop applications worldwide) — Adobe's Reader has dominated the PDF viewer market for decades with install bases commonly reported in the hundreds of millions to billions, so the potential exposed population is effectively the product's entire user base until Adobe's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.