CVE-2026-81983
massOut-of-Bounds Write in Adobe Acrobat Reader Enables Arbitrary Code Execution
Adobe Acrobat Reader contains an out-of-bounds write (CWE-787) flaw in its file-parsing code that can lead to arbitrary code execution with the privileges of the current user. The bug is triggered when a victim opens a malicious file, such as a crafted PDF, which is reflected in the local attack vector (AV:L) and user-interaction requirement behind the 7.8 High CVSS score. Anyone running an affected build of Acrobat Reader is exposed; the available data does not enumerate specific affected version ranges, so defenders should check Adobe's advisory for exact versions. Exploitation is not currently observed: there is no public proof-of-concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days. If exploited, an attacker gains code execution in the logged-in user's context, so the impact scales with the privileges of the account that opens the file.
What to do: Update Acrobat Reader to the patched release identified in Adobe's security bulletin and verify installed builds against the advisory's affected-version list. Until patching is complete, treat unsolicited PDFs from untrusted sources with caution and keep Reader's sandboxed Protected Mode enabled to limit the impact of successful exploitation.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.