AI analysis
Adobe Acrobat Reader (the DC variant is cited in the related ZDI-26-669 advisory) contains an out-of-bounds read (CWE-125) in its JBIG2 file parsing code that reads beyond allocated memory buffers. Exploitation requires user interaction: a victim must open a malicious PDF file for the parsing flaw to trigger. A successful attacker gains disclosure of sensitive process memory (CVSS confidentiality impact rated High), but the flaw cannot modify files or execute code, which is why the severity is Medium (5.5). Any user running an affected Acrobat Reader build is technically exposed, though the practical attack surface is limited to those who open PDFs from untrusted sources. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days (8th percentile).
What to do: Install the Acrobat Reader security update referenced in Adobe's bulletin for CVE-2026-81978, verifying exact affected and patched builds there since they are not provided in this data. Until patched, caution users against opening PDFs from untrusted or unsolicited sources, and consider disabling or sandboxing JBIG2 handling where policy allows. Because the flaw requires user interaction and only discloses memory contents, treat this as a routine-patch-severity item rather than an emergency.
Affected
| Adobe Acrobat Reader (including Acrobat Reader DC per ZDI-26-669) | — |
Estimated exposure
masshundreds of millions of users (Reader is the dominant desktop PDF viewer) — Adobe Acrobat Reader is the most widely deployed PDF viewer worldwide, with Adobe historically reporting hundreds of millions of active users and billions of cumulative installs, so the plausible affected user base is far above the mass…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.