ZeroHour

CVE-2026-81981

mass

Out-of-Bounds Write Leading to Arbitrary Code Execution in Adobe Acrobat Reader

CVSS 3.1
7.8 high
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-81981 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. It is triggered by user interaction: the victim must open a maliciously crafted PDF file, typically delivered via phishing or another social-engineering channel. An attacker who succeeds gains code execution in the user's context, with high impact on confidentiality, integrity, and availability, though not elevated (admin) privileges. Anyone running an affected build of Acrobat Reader is exposed; the source data does not specify affected version ranges. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (6th percentile), so no exploitation is known at this time.

What to do: Update Acrobat Reader to the latest patched release per Adobe's security advisory (fixed build numbers are not included in this data), and verify installed versions on endpoints to prioritize patching. Until systems are patched, keep Protected Mode/Protected View sandboxing enabled and warn users not to open unsolicited or unexpected PDF attachments, since exploitation requires the victim to open a malicious file. No public PoC or confirmed in-the-wild exploitation is known, and the 30-day exploitation probability (EPSS) is low at 0.2%, but patching should still be treated as routine-high priority given the product's ubiquity.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF viewer) — Acrobat Reader is the most widely deployed desktop PDF reader on Windows and macOS, with public market-share data consistently placing it in the large majority of PDF-viewer installs, implying an order of magnitude in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81981, an out-of-bounds write in Adobe Acrobat Reader DC annotation handling that permits remote code execution.

Zero Day Initiative advisory ZDI-26-674 details an out-of-bounds write in the annotation handling of Adobe Acrobat Reader DC. Successful exploitation allows arbitrary code execution after the victim opens a malicious file or visits a malicious page. The advisory carries a CVSS score of 7.8. No exploitation is reported.