AI analysis
Adobe Acrobat Reader contains a use-after-free (CWE-416) memory corruption vulnerability that can allow arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted file, most plausibly a PDF, making user interaction a required part of any attack. An attacker who successfully exploits it gains code execution under the victim's account, with high confidentiality, integrity and availability impact, though they do not gain privileges beyond that user. Anyone running a vulnerable version of Acrobat Reader is affected, including typical desktop and enterprise deployments of the widely used PDF viewer. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation within 30 days.
What to do: Apply Adobe's patched release for CVE-2026-81990 as soon as it is available, checking installed Acrobat Reader versions against the fixed versions listed in Adobe's advisory. Until patched, instruct users not to open PDFs or other files from untrusted sources, as exploitation requires opening a malicious file. Given the very low EPSS and absence of public exploits, routine patch-cycle remediation is reasonable for most environments.
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the world's dominant desktop PDF viewer, deployed on the vast majority of Windows and macOS endpoints) — Estimate is based on Acrobat Reader's status as the default PDF reader on most enterprise and consumer desktops, with Adobe historically reporting hundreds of millions of users, though the count of users on the specific vulnerable version…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.