ZeroHour

CVE-2026-80161

mass

Type Confusion Vulnerability in Adobe Acrobat Reader Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-80161 is a type confusion (CWE-843) vulnerability in Adobe Acrobat Reader that occurs when the application accesses a resource using an incompatible type, potentially corrupting memory during document processing. It is triggered when a victim opens a maliciously crafted file, such as an untrusted PDF, meaning the attack requires user interaction but no special privileges or network access. A successful exploit allows the attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. All users of the affected Acrobat Reader versions identified in Adobe's advisory are exposed, and the flaw is rated High severity (CVSS 7.8). As of now there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.2% probability of exploitation in the next 30 days.

What to do: Consult Adobe's security advisory for the affected version ranges and apply the patched Acrobat Reader release once published; the specific fixed versions were not included in the available data. In the interim, instruct users not to open PDFs from untrusted sources and consider blocking or sandboxing PDF attachments in email gateways and browsers. Inventory endpoints for Acrobat Reader installations to prioritize patching, since exploitation requires only a user opening one malicious file.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the world's dominant PDF viewer) — Acrobat Reader is the de facto default PDF viewer on Windows and macOS with hundreds of millions of installs, so essentially every enterprise endpoint fleet and most consumer desktops are plausibly in scope.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

ZDI disclosed a type confusion RCE (CVE-2026-80161, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction to exploit.

The Zero Day Initiative published advisory ZDI-26-671 for a Dialog Object type confusion vulnerability in Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when a user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-80161. The advisory does not report active exploitation.