ZeroHour

CVE-2026-81976

mass

Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted PDF file, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the logged-in user who opened the file, potentially allowing malware installation or data theft on that endpoint. Anyone running an affected version of Acrobat Reader is exposed, and because Reader is opened on untrusted PDFs from email and the web, attack surface is broad despite the local attack vector. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Check Adobe's security bulletin for this CVE and update Acrobat Reader to the patched version it specifies for your platform. In the interim, warn users not to open PDFs from untrusted sources and consider blocking or sandboxing PDF attachments at the email gateway. Verify endpoint inventories for out-of-date Reader installations and confirm post-update that the fix is deployed.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (global installed base of Acrobat Reader) — Adobe Acrobat Reader is the dominant free PDF viewer with hundreds of millions of active users worldwide according to Adobe's own published figures, so essentially every organization and consumer endpoint fleet is plausibly affected until…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed a CVSS 7.8 use-after-free remote code execution flaw (CVE-2026-81976) in Adobe Acrobat Reader DC triggered via malicious PDFs.

The Zero Day Initiative published advisory ZDI-26-675 describing a use-after-free remote code execution vulnerability in Adobe Acrobat Reader DC, tracked as CVE-2026-81976 with a CVSS 7.8 score. The flaw resides in the annotation feature. Exploitation requires user interaction: the target must visit a malicious page or open a malicious file. The advisory reports no evidence of in-the-wild exploitation.