ZeroHour

CVE-2026-81978

mass

Out-of-Bounds Read in Adobe Acrobat Reader JBIG2 Parsing Leaks Sensitive Memory

CVSS 3.1
5.5 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

Adobe Acrobat Reader (the DC variant is cited in the related ZDI-26-669 advisory) contains an out-of-bounds read (CWE-125) in its JBIG2 file parsing code that reads beyond allocated memory buffers. Exploitation requires user interaction: a victim must open a malicious PDF file for the parsing flaw to trigger. A successful attacker gains disclosure of sensitive process memory (CVSS confidentiality impact rated High), but the flaw cannot modify files or execute code, which is why the severity is Medium (5.5). Any user running an affected Acrobat Reader build is technically exposed, though the practical attack surface is limited to those who open PDFs from untrusted sources. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days (8th percentile).

What to do: Install the Acrobat Reader security update referenced in Adobe's bulletin for CVE-2026-81978, verifying exact affected and patched builds there since they are not provided in this data. Until patched, caution users against opening PDFs from untrusted or unsolicited sources, and consider disabling or sandboxing JBIG2 handling where policy allows. Because the flaw requires user interaction and only discloses memory contents, treat this as a routine-patch-severity item rather than an emergency.

Affected
Adobe Acrobat Reader (including Acrobat Reader DC per ZDI-26-669)
Estimated exposure
masshundreds of millions of users (Reader is the dominant desktop PDF viewer) — Adobe Acrobat Reader is the most widely deployed PDF viewer worldwide, with Adobe historically reporting hundreds of millions of active users and billions of cumulative installs, so the plausible affected user base is far above the mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI advisory ZDI-26-669 details an out-of-bounds read (CVE-2026-81978) when Adobe Acrobat Reader DC parses JBIG2 files.

The Zero Day Initiative published advisory ZDI-26-669 for an out-of-bounds read triggered when Acrobat Reader DC parses JBIG2 files. Successful exploitation allows a remote attacker to disclose sensitive information from affected installations. User interaction is required, such as opening a malicious file or visiting a malicious page. ZDI rated the issue 3.3 and assigned CVE-2026-81978.