ZeroHour

CVE-2026-81986

mass

Use-After-Free in Adobe Acrobat Reader Enables Code Execution via Malicious File

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free memory corruption flaw (CWE-416) that occurs when the application references freed memory while processing a crafted file. The bug is triggered locally when a victim opens an attacker-supplied malicious file, typically a PDF, in an affected Reader build, so no network-facing service is involved and user interaction is required. Successful exploitation allows arbitrary code execution in the context of the current user, meaning an attacker gains the victim's privileges, which can mean full account compromise if that user runs with administrator rights. Anyone running an affected version of Acrobat Reader is exposed; the source data does not enumerate specific version ranges, so defenders should check Adobe's security bulletin for the exact affected and fixed builds. Exploitation status is currently quiet: there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.

What to do: Update Acrobat Reader to the fixed release identified in Adobe's security bulletin for this CVE once published, covering the Reader builds Adobe lists as affected. Until patching is complete, treat unsolicited PDFs and files from untrusted sources as suspect, since exploitation requires a victim to open the malicious file, and keep Reader's Protected Mode (sandbox) enabled to constrain any code execution. Given the low EPSS and absence of a public PoC or KEV listing, there is no current evidence of active targeting, so routine patch cadence is sufficient.

Affected
Adobe Acrobat Reader
Estimated exposure
mass≈1 billion+ potential installations (Acrobat Reader is the dominant desktop PDF viewer) — Adobe has long cited over one billion Acrobat Reader installations and the product is the default PDF viewer across much of the Windows and macOS installed base, so essentially every desktop fleet contains at least some affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81986, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC annotation handling rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-664 for a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81986.