ZeroHour

CVE-2026-81984

mass

Use-After-Free Information Disclosure in Adobe Acrobat Reader Annotation Handling

CVSS 3.1
5.5 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) in its annotation processing, tracked as ZDI-26-668, that can leak sensitive memory contents. An attacker triggers the flaw by crafting a malicious PDF file and persuading a victim to open it, since exploitation requires local user interaction. Successful exploitation discloses sensitive information from memory, though it does not allow code execution or file modification. All users of Adobe Acrobat Reader who open untrusted PDF files are potentially affected, with the reader's enormous installed base making broad exposure likely. As of now there is no known public proof-of-concept, the vulnerability is not in CISA's Known Exploited Vulnerabilities catalog, and the EPSS score of 0.2% indicates low expected near-term exploitation.

What to do: Update Acrobat Reader to the latest release available from Adobe's security bulletin (specific patched versions are not listed in the available data, so verify against the official Adobe advisory for CVE-2026-81984). Until patched, avoid opening PDF files from untrusted or unverified sources and consider configuring Reader for Protected Mode/Protected View. Check deployed Reader versions across endpoints and prioritize patching users who regularly handle PDF attachments from external parties.

Affected
Adobe Acrobat Reader (DC)
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader worldwide) — Adobe's Acrobat Reader is the de facto default PDF viewer on Windows and macOS with a user base commonly cited in the hundreds of millions, so essentially any organization with desktop PDF viewing is exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

ZDI advisory ZDI-26-668 reports an annotation use-after-free (CVE-2026-81984) causing information disclosure in Adobe Acrobat Reader DC.

The Zero Day Initiative published advisory ZDI-26-668 for a use-after-free condition in the annotation feature of Adobe Acrobat Reader DC. Exploitation allows remote attackers to disclose sensitive information when the target opens a malicious file or page. ZDI rated the issue 3.3 on the CVSS scale and assigned CVE-2026-81984.