CVE-2026-81992
massHeap-Based Buffer Overflow in Adobe Acrobat Reader Allows Arbitrary Code Execution
Adobe Acrobat Reader contains a heap-based buffer overflow (CWE-122) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered locally: a victim must open a malicious file, typically a crafted PDF, so an attacker cannot exploit it without user interaction. Successful exploitation gives the attacker code execution with the victim's privileges, which in enterprise environments can be a foothold for lateral movement and data theft. Anyone running an affected Acrobat Reader build is exposed; the available data does not specify affected version ranges, so users should consult Adobe's security bulletin for exact versions and fixed releases. Exploitation status is currently calm: no public proof-of-concept, no listing in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.
What to do: Upgrade Acrobat/Reader to the fixed release identified in Adobe's security bulletin for CVE-2026-81992, and verify that auto-update is enabled across endpoints. Until patched, instruct users not to open PDFs from untrusted sources, since opening a malicious file is the required trigger. With no known in-the-wild exploitation or public PoC, treat this as a high-priority routine patch rather than an emergency.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.