AI analysis
Adobe Acrobat Reader contains an out-of-bounds read vulnerability (CWE-125) in its handling of Doc objects, per the ZDI-26-670 advisory, allowing the application to read beyond intended memory boundaries and potentially expose sensitive memory contents. An attacker triggers it by crafting a malicious PDF and convincing a victim to open it in Acrobat Reader, since exploitation requires local access and user interaction (AV:L/UI:R). A successful attack yields disclosure of sensitive information only; the CVSS vector (C:H/I:N/A:N) shows no integrity or availability impact and no implied code execution. All users of the affected Acrobat Reader/Acrobat DC versions are potentially exposed, though Adobe has not published the exact version ranges in the available data. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days (7th percentile).
What to do: Update Acrobat Reader/Acrobat DC using the fix in Adobe's security bulletin for CVE-2026-81991 as soon as it is available; because exact affected version ranges are not provided here, verify your installed Reader/DC build against Adobe's advisory. Until patched, avoid opening PDFs from untrusted sources and consider filtering unexpected PDF attachments at the email gateway, since exploitation requires a user to open a malicious file.
Affected
| Adobe Acrobat Reader | — |
| Adobe Acrobat Pro DC (Doc Object handling, per ZDI-26-670) | — |
Estimated exposure
masshundreds of millions of users/devices (Acrobat Reader is the dominant desktop PDF viewer) — Based on Acrobat Reader's position as the de facto default PDF viewer across consumer and enterprise Windows/macOS installs, the plausible affected population is in the hundreds of millions, though only users of the affected (not yet…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.