CVE-2026-81979
massOut-of-Bounds Write Code Execution Flaw in Adobe Acrobat Reader
Adobe Acrobat Reader is affected by an out-of-bounds write vulnerability (CWE-787) that can be triggered when a victim opens a malicious file, typically a crafted PDF. Writing past the bounds of an allocated buffer can allow the attacker to achieve arbitrary code execution in the context of the current user, meaning the attacker inherits the privileges of whoever opened the file. The CVSS vector confirms the attack is local and user-interaction dependent: the malicious file must be delivered (e.g., via phishing or an email attachment) and opened by the victim. Any user running an affected version of Adobe Acrobat Reader is exposed, spanning consumer and enterprise desktop estates. There is currently no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days, so no known exploitation exists.
What to do: Deploy the patched Acrobat Reader build referenced in Adobe's security bulletin for CVE-2026-81979 as soon as it is available, and audit endpoint update status across the estate. Until patched, treat unsolicited or untrusted PDF files with caution (e.g., email attachment warnings, sandboxed or preview-only viewing) and ensure Reader's protected mode/sandbox remains enabled. As a precaution, review EDR telemetry for suspicious child-process launches following PDF opens.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.