ZeroHour

CVE-2026-81987

mass

Integer Overflow Leading to Arbitrary Code Execution in Adobe Acrobat Reader

CVSS 3.1
7.8 high
EPSS
<1%p9
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains an integer overflow or wraparound flaw (CWE-190) that can result in arbitrary code execution in the context of the current user. Triggering the flaw requires user interaction: a victim must open a maliciously crafted file, typically a PDF, delivered for example via email or web download. A successful attacker gains code execution with the victim's user privileges, which can enable malware installation, data theft, or lateral movement in enterprise environments. Any user running an affected Acrobat Reader version is at risk, but the specific affected version ranges and platforms are not listed in the available data and should be confirmed in Adobe's security bulletin. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns a low 0.2% probability of exploitation within the next 30 days.

What to do: Consult Adobe's security bulletin for this CVE to determine which versions and platforms are affected, then deploy the corresponding patched release as soon as it is available. Until systems are patched, instruct users not to open PDF files from untrusted or unexpected sources, since exploitation requires opening a malicious file. Track the advisory for any updated affected-version or mitigation details.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is one of the world's most widely deployed desktop applications) — Acrobat Reader is the dominant PDF viewer across consumer and enterprise desktops with an installed base in the hundreds of millions, and because the data omits a narrow affected version range, a large share of the user base is plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI discloses CVE-2026-81987, an integer overflow in Adobe Acrobat Pro DC JPEG parsing enabling remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-658 covering an integer overflow in Adobe Acrobat Pro DC's parsing of JPEG files. Successful exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned a CVSS score of 7.8 and tracked the flaw as CVE-2026-81987.