ZeroHour

CVE-2026-81988

mass

Use-After-Free in Adobe Acrobat Reader Enables Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-reuse flaw that, when successfully exploited, allows arbitrary code execution in the context of the current user. The flaw is triggered by user interaction: a victim must open a maliciously crafted file (typically a PDF) with an affected version of Reader. A successful attacker gains code execution with the victim's user privileges, enough to run malware, steal files, or pivot on the workstation, though no privilege escalation beyond the current user is implied. Everyone running a vulnerable build of Acrobat Reader is affected; given the product's ubiquity on enterprise and consumer desktops, the exposed population is very large, and exact affected version ranges should be taken from Adobe's security bulletin. There is no known public proof of concept, the issue is not on CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so exploitation status is currently none known.

What to do: Upgrade Acrobat Reader to the fixed release identified in Adobe's security bulletin (no specific fixed version is included in this data), using Reader's built-in updater or enterprise deployment tooling and verifying the installed version via Help > About. Until patched, discourage opening PDFs from untrusted sources and apply email gateway filtering of attachments. No public PoC or in-the-wild exploitation is known, so standard patch-cycle timelines are defensible, though high-volume PDF-handling users should be prioritized.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader, with 1B+ cumulative installs) — Acrobat Reader is the de facto default PDF viewer on a very large share of enterprise and consumer desktops, so even a subset of its 1B+ historical install base implies far more users than most enterprise software flaws affect.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81988, a use-after-free in Adobe Acrobat Pro DC document object handling that enables remote code execution.

Zero Day Initiative advisory ZDI-26-673 describes a use-after-free vulnerability in the document object handling of Adobe Acrobat Pro DC. Arbitrary code execution is possible when a target opens a malicious file or visits a malicious page. The flaw received a CVSS rating of 7.8. No in-the-wild exploitation is reported.