ZeroHour

CVE-2026-79909

mass

Use-After-Free Code Execution Flaw in Adobe Acrobat Reader

CVSS 3.1
7.8 high
EPSS
<1%p6
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. The flaw is triggered locally when a victim opens a maliciously crafted PDF file, so the attack vector requires user interaction rather than network-reachable exploitation. A successful attacker gains the privileges of the user running Reader, which typically means access to that user's files and session on the workstation. All users of the affected Acrobat Reader builds are potentially exposed, as the data does not enumerate specific version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and its EPSS score of 0.2% (6th percentile) indicates a low near-term likelihood of exploitation in the wild.

What to do: Monitor Adobe's Security Bulletins (APSB advisories) for this CVE and apply the patched Reader build via Adobe's updater as soon as it is released, since the data does not yet list fixed versions. In the interim, warn users not to open PDF attachments or downloads from untrusted senders, as exploitation requires opening a malicious file. Verify deployed Reader versions across your estate using software inventory so you can prioritize patching once Adobe publishes the fixed releases.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Reader is the world's dominant PDF viewer) — Adobe Acrobat Reader is the default or primary PDF reader on an enormous share of Windows and macOS endpoints, with hundreds of millions of active users and billions of cumulative installs, so essentially every organization with desktop…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-79909, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC rated CVSS 7.8, requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-665 for a use-after-free vulnerability in Adobe Acrobat Reader DC's Annots processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-79909.