ZeroHour

CVE-2026-79910

mass

Out-of-bounds read in Adobe Acrobat Reader JPEG2000 parsing leaks sensitive memory

CVSS 3.1
5.5 medium
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-79910 is an out-of-bounds read (CWE-125) in the JPEG2000 file-parsing code of Adobe Acrobat Reader DC, which allows the application to read beyond the intended memory boundary when processing a crafted file. It is triggered when a victim opens a malicious file, most plausibly a PDF containing malformed JPEG2000 (JPX) image data, so user interaction is required (CVSS UI:R, local attack vector, scored 5.5 medium). A successful attack yields disclosure of sensitive process memory (high confidentiality impact, no integrity or availability impact); it is an information-disclosure flaw, not code execution. Anyone running an affected desktop build of Acrobat Reader is potentially exposed, though only when opening attacker-supplied files. There is currently no known exploitation, no public proof of concept, the EPSS probability is low (0.2% in 30 days, 7th percentile), and it is not in CISA KEV.

What to do: Update Acrobat/Reader to the patched build cited for CVE-2026-79910 in Adobe's security bulletin, using Help > Check for Updates or the installer from the bulletin, and verify the installed version afterwards. Until patched, be cautious with PDFs from untrusted sources and keep Reader's Protected Mode/Enhanced Security enabled, since the flaw only leaks memory when a victim opens a crafted file. Because only affected parsing code is involved and there is no known exploitation, this is a routine patch-cycle priority rather than an emergency.

Affected
Adobe Acrobat Reader (DC)
Estimated exposure
mass≈100M+ desktop installations (Reader is the world's dominant PDF viewer) — Adobe's Reader/Acrobat DC has an installed base in the hundreds of millions of users (billions of cumulative downloads historically), so the potential exposure is order-of-magnitude 10^7–10^8, though actual risk requires a user to open a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI advisory ZDI-26-666 details an out-of-bounds read (CVE-2026-79910) when Adobe Acrobat Reader DC parses JPEG2000 files.

The Zero Day Initiative published advisory ZDI-26-666 for an out-of-bounds read triggered when Acrobat Reader DC parses JPEG2000 files. Successful exploitation allows a remote attacker to disclose sensitive information from affected installations. User interaction is required, such as opening a malicious file or visiting a malicious page. ZDI rated the issue 3.3 and assigned CVE-2026-79910.