ZeroHour
Product

Adobe Acrobat Reader DC

14 mentions in 7 days · 14 in 30 days · 14 total · first seen · last

Timeline

ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-667 for a use-after-free vulnerability in the annotation feature of Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when the user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-81975. The advisory does not state whether exploitation has been observed.

ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability

ZDI disclosed CVE-2026-81977, an integer underflow in Adobe Acrobat Reader DC PDF parsing that enables sensitive information disclosure.

Zero Day Initiative advisory ZDI-26-672 reports an integer underflow in PDF file parsing in Adobe Acrobat Reader DC. A remote attacker could disclose sensitive information, but exploitation requires the victim to open a malicious file or visit a malicious page. The flaw carries a low CVSS score of 3.3. No exploitation is reported.

ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI advisory ZDI-26-666 details an out-of-bounds read (CVE-2026-79910) when Adobe Acrobat Reader DC parses JPEG2000 files.

The Zero Day Initiative published advisory ZDI-26-666 for an out-of-bounds read triggered when Acrobat Reader DC parses JPEG2000 files. Successful exploitation allows a remote attacker to disclose sensitive information from affected installations. User interaction is required, such as opening a malicious file or visiting a malicious page. ZDI rated the issue 3.3 and assigned CVE-2026-79910.

ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81973, a use-after-free in Adobe Acrobat Reader DC digital signature handling that enables remote code execution.

Zero Day Initiative advisory ZDI-26-676 describes a use-after-free vulnerability in the DigSig (digital signature) feature of Adobe Acrobat Reader DC. Exploitation requires the target to open a malicious file or visit a malicious page, after which arbitrary code can execute. The flaw carries a CVSS score of 7.8. No in-the-wild exploitation is reported.

ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

ZDI discloses CVE-2026-80162, a font-parsing use-after-free in Adobe Acrobat Reader DC enabling limited sensitive information disclosure with CVSS 3.3.

The Zero Day Initiative published ZDI-26-660 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's font parsing. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80162.

ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-661 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the flaw CVSS 7.8 and assigned CVE-2026-81985.

ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

ZDI disclosed a type confusion RCE (CVE-2026-80161, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction to exploit.

The Zero Day Initiative published advisory ZDI-26-671 for a Dialog Object type confusion vulnerability in Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when a user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-80161. The advisory does not report active exploitation.

ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81986, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC annotation handling rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-664 for a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81986.

ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI discloses CVE-2026-80160, an out-of-bounds read in Adobe Acrobat Reader DC JPEG2000 parsing enabling sensitive information disclosure with CVSS 3.3.

The Zero Day Initiative published ZDI-26-659 covering an out-of-bounds read in Adobe Acrobat Reader DC's parsing of JPEG2000 files. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80160.

ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-81981, an out-of-bounds write in Adobe Acrobat Reader DC annotation handling that permits remote code execution.

Zero Day Initiative advisory ZDI-26-674 details an out-of-bounds write in the annotation handling of Adobe Acrobat Reader DC. Successful exploitation allows arbitrary code execution after the victim opens a malicious file or visits a malicious page. The advisory carries a CVSS score of 7.8. No exploitation is reported.

ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI discloses CVE-2026-81990, a use-after-free in Adobe Acrobat Reader DC annotation handling allowing remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-662 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Successful exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned a CVSS score of 7.8 and tracked the flaw as CVE-2026-81990.

ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

ZDI advisory ZDI-26-668 reports an annotation use-after-free (CVE-2026-81984) causing information disclosure in Adobe Acrobat Reader DC.

The Zero Day Initiative published advisory ZDI-26-668 for a use-after-free condition in the annotation feature of Adobe Acrobat Reader DC. Exploitation allows remote attackers to disclose sensitive information when the target opens a malicious file or page. ZDI rated the issue 3.3 on the CVSS scale and assigned CVE-2026-81984.

ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI advisory ZDI-26-669 details an out-of-bounds read (CVE-2026-81978) when Adobe Acrobat Reader DC parses JBIG2 files.

The Zero Day Initiative published advisory ZDI-26-669 for an out-of-bounds read triggered when Acrobat Reader DC parses JBIG2 files. Successful exploitation allows a remote attacker to disclose sensitive information from affected installations. User interaction is required, such as opening a malicious file or visiting a malicious page. ZDI rated the issue 3.3 and assigned CVE-2026-81978.

ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-79909, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC rated CVSS 7.8, requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-665 for a use-after-free vulnerability in Adobe Acrobat Reader DC's Annots processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-79909.

Related CVEs

  • Use-After-Free Code Execution Flaw in Adobe Acrobat Reader
    Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that an attacker can leverage for arbitrary code execution. The flaw is triggered when a victim opens a maliciously crafted file, such as a booby-trapped PDF, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the currently logged-in user, which could allow installation of malware, data theft, or further lateral movement on the workstation. Anyone running an affected release of Adobe Acrobat Reader is exposed; the source data does not enumerate specific affected version ranges, so defenders should consult Adobe's security bulletin (APSB) for exact versions and platforms. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only about 0.2%.
    · Adobe Acrobat Readermass
  • Out-of-Bounds Write Leading to Arbitrary Code Execution in Adobe Acrobat Reader
    CVE-2026-81981 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. It is triggered by user interaction: the victim must open a maliciously crafted PDF file, typically delivered via phishing or another social-engineering channel. An attacker who succeeds gains code execution in the user's context, with high impact on confidentiality, integrity, and availability, though not elevated (admin) privileges. Anyone running an affected build of Acrobat Reader is exposed; the source data does not specify affected version ranges. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (6th percentile), so no exploitation is known at this time.
    · Adobe Acrobat Readermass
  • Type Confusion Vulnerability in Adobe Acrobat Reader Allows Arbitrary Code Execution
    CVE-2026-80161 is a type confusion (CWE-843) vulnerability in Adobe Acrobat Reader that occurs when the application accesses a resource using an incompatible type, potentially corrupting memory during document processing. It is triggered when a victim opens a maliciously crafted file, such as an untrusted PDF, meaning the attack requires user interaction but no special privileges or network access. A successful exploit allows the attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. All users of the affected Acrobat Reader versions identified in Adobe's advisory are exposed, and the flaw is rated High severity (CVSS 7.8). As of now there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.2% probability of exploitation in the next 30 days.
    · Adobe Acrobat Readermass
  • Use-After-Free in Adobe Acrobat Reader Allows Code Execution When Opening Files
    Adobe Acrobat Reader contains a use-after-free memory-corruption flaw (CWE-416) that can be triggered when the application processes a maliciously crafted file. Exploitation requires user interaction: the victim must open the malicious file, making this a local attack vector in which the user's own privileges are at stake. A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity and availability of that user's environment. Any user running Adobe Acrobat Reader is potentially affected; the available data does not specify which version ranges are impacted, so consult Adobe's security advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS assigns just a 0.2% probability of exploitation within 30 days (10th percentile), indicating low near-term exploitation risk.
    · Adobe Acrobat Readermass
  • Use-After-Free in Adobe Acrobat Reader Enables Code Execution via Malicious File
    Adobe Acrobat Reader contains a use-after-free memory corruption flaw (CWE-416) that occurs when the application references freed memory while processing a crafted file. The bug is triggered locally when a victim opens an attacker-supplied malicious file, typically a PDF, in an affected Reader build, so no network-facing service is involved and user interaction is required. Successful exploitation allows arbitrary code execution in the context of the current user, meaning an attacker gains the victim's privileges, which can mean full account compromise if that user runs with administrator rights. Anyone running an affected version of Acrobat Reader is exposed; the source data does not enumerate specific version ranges, so defenders should check Adobe's security bulletin for the exact affected and fixed builds. Exploitation status is currently quiet: there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.
    · Adobe Acrobat Readermass
  • Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution
    Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk.
    · Adobe Acrobat Readermass
  • Use-After-Free Code Execution Flaw in Adobe Acrobat Reader
    Adobe Acrobat Reader contains a use-after-free (CWE-416) memory corruption vulnerability that can allow arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted file, most plausibly a PDF, making user interaction a required part of any attack. An attacker who successfully exploits it gains code execution under the victim's account, with high confidentiality, integrity and availability impact, though they do not gain privileges beyond that user. Anyone running a vulnerable version of Acrobat Reader is affected, including typical desktop and enterprise deployments of the widely used PDF viewer. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation within 30 days.
    · Adobe Acrobat Readermass
  • Out-of-Bounds Read in Adobe Acrobat Reader JBIG2 Parsing Leaks Sensitive Memory
    Adobe Acrobat Reader (the DC variant is cited in the related ZDI-26-669 advisory) contains an out-of-bounds read (CWE-125) in its JBIG2 file parsing code that reads beyond allocated memory buffers. Exploitation requires user interaction: a victim must open a malicious PDF file for the parsing flaw to trigger. A successful attacker gains disclosure of sensitive process memory (CVSS confidentiality impact rated High), but the flaw cannot modify files or execute code, which is why the severity is Medium (5.5). Any user running an affected Acrobat Reader build is technically exposed, though the practical attack surface is limited to those who open PDFs from untrusted sources. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days (8th percentile).
    · Adobe Acrobat Reader (including Acrobat Reader DC per ZDI-26-669)mass
  • Use-After-Free in Adobe Acrobat Reader Font Parsing Leaks Sensitive Memory
    Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) in its font-parsing code that can expose sensitive contents of process memory. An attacker triggers it by crafting a malicious file (e.g., a PDF with specially formed font data) that a victim must open, so exploitation requires user interaction. Successful exploitation results in disclosure of sensitive information from memory, with no direct impact on data integrity or system availability, and the CVSS score of 5.5 (medium) reflects this read-only, local attack vector. Anyone running Adobe Acrobat Reader could be affected if they open an attacker-supplied file. As of now there is no known exploitation in the wild, no public proof-of-concept, and the EPSS probability of exploitation within 30 days is low at 0.2%; the flaw is also not in CISA's KEV catalog.
    · Adobe Acrobat Reader (including Acrobat Reader DC)mass
  • Integer Underflow Information Disclosure in Adobe Acrobat Reader
    Adobe Acrobat Reader contains an integer underflow (wrap or wraparound) flaw, CWE-191, that occurs during PDF file parsing and can lead to the disclosure of sensitive memory. The vulnerability is triggered when a victim opens a maliciously crafted PDF file, making user interaction a required part of any attack. An attacker who successfully exploits it can read sensitive information from the application's memory, which could expose data in the affected process and potentially aid further attacks; the flaw does not by itself allow code execution. Anyone running the affected versions of Acrobat Reader (identified in related coverage as Acrobat Reader DC) who opens PDFs from untrusted sources is exposed. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.2% probability of exploitation within 30 days, so no active exploitation is known.
    · Adobe Acrobat Reader (Acrobat Reader DC)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.