CVE-2026-81980
massOut-of-bounds write in Adobe Acrobat Reader allows code execution via malicious PDFs
Adobe Acrobat Reader contains an out-of-bounds write (CWE-787) that an attacker can leverage to execute arbitrary code with the privileges of the current user. The flaw is triggered when a victim opens a specially crafted malicious file, most likely a malicious PDF, making user interaction a prerequisite for exploitation. A successful attacker gains code execution in the context of the logged-in user, which can lead to malware installation, data theft, or lateral movement in enterprise environments. Anyone running Adobe Acrobat Reader on a vulnerable build is affected, and given the product's ubiquity the potential population is very large. There is currently no evidence of exploitation: the issue is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a low 0.2% probability of exploitation within 30 days.
What to do: Install the Acrobat Reader update referenced in Adobe's security bulletin as soon as it is available (exact fixed version numbers are not provided in the CVE data). Until patched, caution users against opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Because exploitation requires user interaction and no PoC is public, immediate risk is low, but fleet-wide patching should be prioritized given the large installed base.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.