ZeroHour

CVE-2026-81989

mass

Use-After-Free Arbitrary Code Execution in Adobe Acrobat Reader

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-corruption bug that can be leveraged for arbitrary code execution in the context of the current user. The flaw is triggered only with user interaction: the victim must open a malicious file, most plausibly a crafted PDF, making this a client-side, socially engineered attack rather than a remote, server-side one. A successful exploit lets an attacker run code with the victim's privileges, enabling data theft, malware installation, or further movement within the environment. Anyone running the affected Acrobat Reader releases is exposed, though the source data does not enumerate specific version ranges. There is currently no sign of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.2% probability of exploitation within 30 days (10th percentile).

What to do: Apply the fix as soon as Adobe's advisory for CVE-2026-81989 identifies it, prioritizing endpoints that routinely open PDFs from untrusted sources; consult the Adobe bulletin for the exact patched versions. In the interim, attachment sandboxing, mail filtering, and user caution with unsolicited PDFs reduce practical risk because exploitation requires opening a malicious file. Since there is no public PoC and no KEV listing, this can be handled through the normal patch cycle rather than as an emergency.

Affected
Adobe Acrobat Reader
Estimated exposure
masson the order of hundreds of millions of users (Acrobat Reader is the dominant desktop PDF viewer) — Estimate is based on deployment patterns: Acrobat Reader is the de facto PDF viewer preinstalled or standard on most Windows and macOS endpoints, giving an installed user base in the hundreds of millions, although only users who actually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81989, a use-after-free remote code execution flaw in Adobe Acrobat Pro DC annotation handling rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-663 for a use-after-free vulnerability in Adobe Acrobat Pro DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81989.