Type Confusion Vulnerability in Adobe Acrobat Reader Allows Arbitrary Code Execution
AI analysis
CVE-2026-80161 is a type confusion (CWE-843) vulnerability in Adobe Acrobat Reader that occurs when the application accesses a resource using an incompatible type, potentially corrupting memory during document processing. It is triggered when a victim opens a maliciously crafted file, such as an untrusted PDF, meaning the attack requires user interaction but no special privileges or network access. A successful exploit allows the attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. All users of the affected Acrobat Reader versions identified in Adobe's advisory are exposed, and the flaw is rated High severity (CVSS 7.8). As of now there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.2% probability of exploitation in the next 30 days.
What to do: Consult Adobe's security advisory for the affected version ranges and apply the patched Acrobat Reader release once published; the specific fixed versions were not included in the available data. In the interim, instruct users not to open PDFs from untrusted sources and consider blocking or sandboxing PDF attachments in email gateways and browsers. Inventory endpoints for Acrobat Reader installations to prioritize patching, since exploitation requires only a user opening one malicious file.
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the world's dominant PDF viewer) — Acrobat Reader is the de facto default PDF viewer on Windows and macOS with hundreds of millions of installs, so essentially every enterprise endpoint fleet and most consumer desktops are plausibly in scope.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.