ZeroHour
Product

Adobe Acrobat Pro DC

4 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81989, a use-after-free remote code execution flaw in Adobe Acrobat Pro DC annotation handling rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-663 for a use-after-free vulnerability in Adobe Acrobat Pro DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81989.

ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI published advisory ZDI-26-670 for an out-of-bounds read information disclosure flaw (CVE-2026-81991) in Adobe Acrobat Pro DC.

The Zero Day Initiative disclosed ZDI-26-670, an out-of-bounds read in the Doc object of Adobe Acrobat Pro DC. A remote attacker could disclose sensitive information from affected installations if the user opens a malicious file or page. ZDI rated the issue 3.3 on the CVSS scale and assigned CVE-2026-81991.

ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI discloses CVE-2026-81987, an integer overflow in Adobe Acrobat Pro DC JPEG parsing enabling remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-658 covering an integer overflow in Adobe Acrobat Pro DC's parsing of JPEG files. Successful exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned a CVSS score of 7.8 and tracked the flaw as CVE-2026-81987.

ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81988, a use-after-free in Adobe Acrobat Pro DC document object handling that enables remote code execution.

Zero Day Initiative advisory ZDI-26-673 describes a use-after-free vulnerability in the document object handling of Adobe Acrobat Pro DC. Arbitrary code execution is possible when a target opens a malicious file or visits a malicious page. The flaw received a CVSS rating of 7.8. No in-the-wild exploitation is reported.

Related CVEs

  • Use-After-Free Arbitrary Code Execution in Adobe Acrobat Reader
    Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-corruption bug that can be leveraged for arbitrary code execution in the context of the current user. The flaw is triggered only with user interaction: the victim must open a malicious file, most plausibly a crafted PDF, making this a client-side, socially engineered attack rather than a remote, server-side one. A successful exploit lets an attacker run code with the victim's privileges, enabling data theft, malware installation, or further movement within the environment. Anyone running the affected Acrobat Reader releases is exposed, though the source data does not enumerate specific version ranges. There is currently no sign of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.2% probability of exploitation within 30 days (10th percentile).
    · Adobe Acrobat Readermass
  • Integer Overflow Leading to Arbitrary Code Execution in Adobe Acrobat Reader
    Adobe Acrobat Reader contains an integer overflow or wraparound flaw (CWE-190) that can result in arbitrary code execution in the context of the current user. Triggering the flaw requires user interaction: a victim must open a maliciously crafted file, typically a PDF, delivered for example via email or web download. A successful attacker gains code execution with the victim's user privileges, which can enable malware installation, data theft, or lateral movement in enterprise environments. Any user running an affected Acrobat Reader version is at risk, but the specific affected version ranges and platforms are not listed in the available data and should be confirmed in Adobe's security bulletin. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns a low 0.2% probability of exploitation within the next 30 days.
    · Adobe Acrobat Readermass
  • Use-After-Free in Adobe Acrobat Reader Enables Arbitrary Code Execution
    Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-reuse flaw that, when successfully exploited, allows arbitrary code execution in the context of the current user. The flaw is triggered by user interaction: a victim must open a maliciously crafted file (typically a PDF) with an affected version of Reader. A successful attacker gains code execution with the victim's user privileges, enough to run malware, steal files, or pivot on the workstation, though no privilege escalation beyond the current user is implied. Everyone running a vulnerable build of Acrobat Reader is affected; given the product's ubiquity on enterprise and consumer desktops, the exposed population is very large, and exact affected version ranges should be taken from Adobe's security bulletin. There is no known public proof of concept, the issue is not on CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so exploitation status is currently none known.
    · Adobe Acrobat Readermass
  • Out-of-Bounds Read Information Disclosure in Adobe Acrobat Reader (Doc Object)
    Adobe Acrobat Reader contains an out-of-bounds read vulnerability (CWE-125) in its handling of Doc objects, per the ZDI-26-670 advisory, allowing the application to read beyond intended memory boundaries and potentially expose sensitive memory contents. An attacker triggers it by crafting a malicious PDF and convincing a victim to open it in Acrobat Reader, since exploitation requires local access and user interaction (AV:L/UI:R). A successful attack yields disclosure of sensitive information only; the CVSS vector (C:H/I:N/A:N) shows no integrity or availability impact and no implied code execution. All users of the affected Acrobat Reader/Acrobat DC versions are potentially exposed, though Adobe has not published the exact version ranges in the available data. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days (7th percentile).
    · Adobe Acrobat Reader · Adobe Acrobat Pro DC (Doc Object handling, per ZDI-26-670)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.