ZeroHour

CVE-2026-81992

mass

Heap-Based Buffer Overflow in Adobe Acrobat Reader Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p11
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a heap-based buffer overflow (CWE-122) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered locally: a victim must open a malicious file, typically a crafted PDF, so an attacker cannot exploit it without user interaction. Successful exploitation gives the attacker code execution with the victim's privileges, which in enterprise environments can be a foothold for lateral movement and data theft. Anyone running an affected Acrobat Reader build is exposed; the available data does not specify affected version ranges, so users should consult Adobe's security bulletin for exact versions and fixed releases. Exploitation status is currently calm: no public proof-of-concept, no listing in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.

What to do: Upgrade Acrobat/Reader to the fixed release identified in Adobe's security bulletin for CVE-2026-81992, and verify that auto-update is enabled across endpoints. Until patched, instruct users not to open PDFs from untrusted sources, since opening a malicious file is the required trigger. With no known in-the-wild exploitation or public PoC, treat this as a high-priority routine patch rather than an emergency.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of desktop installations worldwide — Acrobat Reader is the de facto standard PDF viewer with billions of cumulative desktop installs, so the potential user base is in the hundreds of millions, although exploitation requires a victim to open a malicious file rather than any…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.