ZeroHour

CVE-2026-81980

mass

Out-of-bounds write in Adobe Acrobat Reader allows code execution via malicious PDFs

CVSS 3.1
7.8 high
EPSS
<1%p6
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains an out-of-bounds write (CWE-787) that an attacker can leverage to execute arbitrary code with the privileges of the current user. The flaw is triggered when a victim opens a specially crafted malicious file, most likely a malicious PDF, making user interaction a prerequisite for exploitation. A successful attacker gains code execution in the context of the logged-in user, which can lead to malware installation, data theft, or lateral movement in enterprise environments. Anyone running Adobe Acrobat Reader on a vulnerable build is affected, and given the product's ubiquity the potential population is very large. There is currently no evidence of exploitation: the issue is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a low 0.2% probability of exploitation within 30 days.

What to do: Install the Acrobat Reader update referenced in Adobe's security bulletin as soon as it is available (exact fixed version numbers are not provided in the CVE data). Until patched, caution users against opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Because exploitation requires user interaction and no PoC is public, immediate risk is low, but fleet-wide patching should be prioritized given the large installed base.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the world's most widely deployed PDF reader) — Adobe Acrobat Reader is the de facto default PDF viewer on Windows and macOS with a user base Adobe and industry surveys place in the hundreds of millions, so the potentially affected installed base is mass-scale even though the vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.