ZeroHour

CVE-2026-81975

mass

Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk.

What to do: Check Adobe's security bulletin for CVE-2026-81975 to identify the fixed release and update Acrobat Reader as soon as a patch is available. In the interim, warn users not to open PDFs or other documents from untrusted senders, and consider disabling automatic PDF preview/attachment opening in email clients. Because this is a client-side flaw, endpoint patching coverage is the primary mitigation; verify your software inventory for Acrobat Reader installations across endpoints.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the default PDF reader on a large share of the world's Windows and macOS desktops) — Acrobat Reader is the most widely deployed PDF viewer, with Adobe historically reporting hundreds of millions of monthly active users, so the plausible affected install base is in the hundreds of millions even though the specific…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-667 for a use-after-free vulnerability in the annotation feature of Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when the user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-81975. The advisory does not state whether exploitation has been observed.