ZeroHour

CVE-2026-81983

mass

Out-of-Bounds Write in Adobe Acrobat Reader Enables Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p7
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains an out-of-bounds write (CWE-787) flaw in its file-parsing code that can lead to arbitrary code execution with the privileges of the current user. The bug is triggered when a victim opens a malicious file, such as a crafted PDF, which is reflected in the local attack vector (AV:L) and user-interaction requirement behind the 7.8 High CVSS score. Anyone running an affected build of Acrobat Reader is exposed; the available data does not enumerate specific affected version ranges, so defenders should check Adobe's advisory for exact versions. Exploitation is not currently observed: there is no public proof-of-concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days. If exploited, an attacker gains code execution in the logged-in user's context, so the impact scales with the privileges of the account that opens the file.

What to do: Update Acrobat Reader to the patched release identified in Adobe's security bulletin and verify installed builds against the advisory's affected-version list. Until patching is complete, treat unsolicited PDFs from untrusted sources with caution and keep Reader's sandboxed Protected Mode enabled to limit the impact of successful exploitation.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the world's dominant desktop PDF reader) — Estimate is based on Acrobat Reader's position as the default PDF viewer on an enormous share of Windows and macOS endpoints across consumer and enterprise deployments, implying hundreds of millions of active installations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.