ZeroHour

CVE-2026-80160

mass

Out-of-Bounds Read in Adobe Acrobat Reader JPEG2000 Parsing Leaks Sensitive Memory

CVSS 3.1
5.5 medium
EPSS
<1%p7
Published
()
Modified
AI analysis

Adobe Acrobat Reader is affected by an out-of-bounds read vulnerability (CWE-125) in its parsing of JPEG2000 image data, per the ZDI advisory (ZDI-26-659), which could allow disclosure of sensitive memory contents. The flaw is triggered when a victim opens a maliciously crafted file, meaning user interaction is required for exploitation. A successful attack results in information disclosure (high confidentiality impact, no integrity or availability impact), and the local attack vector and user interaction requirement cap the CVSS 3.1 score at 5.5 (medium). All users running affected versions of Acrobat Reader are potentially exposed. As of now there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Update Acrobat Reader to the patched release identified in Adobe's security bulletin for this CVE (no fixed version number is provided in the source data); confirm the installed version via Help > About and update via Help > Check for Updates. Because exploitation requires opening a malicious file, users should avoid opening PDFs from untrusted sources until patched. No public PoC or in-the-wild exploitation is known, so this can be handled through routine patch cycles rather than emergency response.

Affected
Adobe Acrobat Reader DC (Acrobat Reader)
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader) — Estimate based on Acrobat Reader's near-ubiquitous deployment as the default PDF viewer on Windows and macOS endpoints, with Adobe historically reporting hundreds of millions of users; all users of affected versions are potentially exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI discloses CVE-2026-80160, an out-of-bounds read in Adobe Acrobat Reader DC JPEG2000 parsing enabling sensitive information disclosure with CVSS 3.3.

The Zero Day Initiative published ZDI-26-659 covering an out-of-bounds read in Adobe Acrobat Reader DC's parsing of JPEG2000 files. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80160.