ZeroHour

CVE-2026-81985

mass

Use-After-Free in Adobe Acrobat Reader Allows Code Execution When Opening Files

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free memory-corruption flaw (CWE-416) that can be triggered when the application processes a maliciously crafted file. Exploitation requires user interaction: the victim must open the malicious file, making this a local attack vector in which the user's own privileges are at stake. A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity and availability of that user's environment. Any user running Adobe Acrobat Reader is potentially affected; the available data does not specify which version ranges are impacted, so consult Adobe's security advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS assigns just a 0.2% probability of exploitation within 30 days (10th percentile), indicating low near-term exploitation risk.

What to do: Update Acrobat Reader to the latest release per Adobe's security bulletin for this CVE — the provided data lacks fixed version numbers, so verify the exact affected and patched builds there. Until patched, avoid opening PDFs and other documents from untrusted sources, and consider sandboxing or restricting Acrobat for email-delivered files. With no public PoC and low EPSS, immediate risk is low, but patching should not be deferred given the near-universal deployment base.

Affected
Adobe Acrobat Reader
Estimated exposure
mass≈1 billion+ users (Acrobat Reader is the dominant desktop PDF reader) — Acrobat Reader is the most widely deployed desktop PDF viewer, with cumulative installations reported in the billions, so deployment is effectively universal across consumer and enterprise endpoints.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-661 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the flaw CVSS 7.8 and assigned CVE-2026-81985.