CVE-2026-79908
massOut-of-Bounds Write in Adobe Acrobat Reader Allows Arbitrary Code Execution
Adobe Acrobat Reader contains an out-of-bounds write vulnerability (CWE-787), a memory corruption flaw in which the application writes data past the boundaries of an allocated buffer. The flaw is triggered when a victim opens a maliciously crafted file, most plausibly a PDF, meaning the attack requires user interaction rather than being remotely exploitable on its own. An attacker who successfully exploits it gains the ability to run arbitrary code in the context of the current user, with that user's privileges rather than elevated system rights. Anyone running the affected builds of Acrobat Reader is potentially exposed, and because the reader is opened on countless endpoints daily, malicious-file delivery via email or web download is the realistic attack path. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and its EPSS score of 0.2% (7th percentile) suggests a low near-term probability of exploitation.
What to do: Update Acrobat Reader to the latest release per Adobe's advisory for CVE-2026-79908, since the source data does not list fixed version numbers. As interim mitigations, avoid opening PDFs from untrusted or unexpected sources, ensure the current user runs without administrative rights on endpoints, and verify that email gateways and endpoint security are inspecting PDF attachments. Defenders should treat this as high severity given code execution impact, while noting no known exploitation yet.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.