Use-After-Free Code Execution Flaw in Adobe Acrobat Reader
Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that an attacker can leverage for arbitrary code execution. The flaw is triggered when a victim opens a maliciously crafted file, such as a booby-trapped PDF, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the currently logged-in user, which could allow installation of malware, data theft, or further lateral movement on the workstation. Anyone running an affected release of Adobe Acrobat Reader is exposed; the source data does not enumerate specific affected version ranges, so defenders should consult Adobe's security bulletin (APSB) for exact versions and platforms. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only about 0.2%.
· Adobe Acrobat Readermass
Out-of-Bounds Write Leading to Arbitrary Code Execution in Adobe Acrobat Reader
CVE-2026-81981 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. It is triggered by user interaction: the victim must open a maliciously crafted PDF file, typically delivered via phishing or another social-engineering channel. An attacker who succeeds gains code execution in the user's context, with high impact on confidentiality, integrity, and availability, though not elevated (admin) privileges. Anyone running an affected build of Acrobat Reader is exposed; the source data does not specify affected version ranges. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (6th percentile), so no exploitation is known at this time.
· Adobe Acrobat Readermass
Type Confusion Vulnerability in Adobe Acrobat Reader Allows Arbitrary Code Execution
CVE-2026-80161 is a type confusion (CWE-843) vulnerability in Adobe Acrobat Reader that occurs when the application accesses a resource using an incompatible type, potentially corrupting memory during document processing. It is triggered when a victim opens a maliciously crafted file, such as an untrusted PDF, meaning the attack requires user interaction but no special privileges or network access. A successful exploit allows the attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. All users of the affected Acrobat Reader versions identified in Adobe's advisory are exposed, and the flaw is rated High severity (CVSS 7.8). As of now there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.2% probability of exploitation in the next 30 days.
· Adobe Acrobat Readermass
Use-After-Free in Adobe Acrobat Reader Allows Code Execution When Opening Files
Adobe Acrobat Reader contains a use-after-free memory-corruption flaw (CWE-416) that can be triggered when the application processes a maliciously crafted file. Exploitation requires user interaction: the victim must open the malicious file, making this a local attack vector in which the user's own privileges are at stake. A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity and availability of that user's environment. Any user running Adobe Acrobat Reader is potentially affected; the available data does not specify which version ranges are impacted, so consult Adobe's security advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS assigns just a 0.2% probability of exploitation within 30 days (10th percentile), indicating low near-term exploitation risk.
· Adobe Acrobat Readermass
Use-After-Free in Adobe Acrobat Reader Enables Code Execution via Malicious File
Adobe Acrobat Reader contains a use-after-free memory corruption flaw (CWE-416) that occurs when the application references freed memory while processing a crafted file. The bug is triggered locally when a victim opens an attacker-supplied malicious file, typically a PDF, in an affected Reader build, so no network-facing service is involved and user interaction is required. Successful exploitation allows arbitrary code execution in the context of the current user, meaning an attacker gains the victim's privileges, which can mean full account compromise if that user runs with administrator rights. Anyone running an affected version of Acrobat Reader is exposed; the source data does not enumerate specific version ranges, so defenders should check Adobe's security bulletin for the exact affected and fixed builds. Exploitation status is currently quiet: there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.
· Adobe Acrobat Readermass
Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution
Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk.
· Adobe Acrobat Readermass
Use-After-Free Code Execution Flaw in Adobe Acrobat Reader
Adobe Acrobat Reader contains a use-after-free (CWE-416) memory corruption vulnerability that can allow arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted file, most plausibly a PDF, making user interaction a required part of any attack. An attacker who successfully exploits it gains code execution under the victim's account, with high confidentiality, integrity and availability impact, though they do not gain privileges beyond that user. Anyone running a vulnerable version of Acrobat Reader is affected, including typical desktop and enterprise deployments of the widely used PDF viewer. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation within 30 days.
· Adobe Acrobat Readermass
Out-of-Bounds Read in Adobe Acrobat Reader JBIG2 Parsing Leaks Sensitive Memory
Adobe Acrobat Reader (the DC variant is cited in the related ZDI-26-669 advisory) contains an out-of-bounds read (CWE-125) in its JBIG2 file parsing code that reads beyond allocated memory buffers. Exploitation requires user interaction: a victim must open a malicious PDF file for the parsing flaw to trigger. A successful attacker gains disclosure of sensitive process memory (CVSS confidentiality impact rated High), but the flaw cannot modify files or execute code, which is why the severity is Medium (5.5). Any user running an affected Acrobat Reader build is technically exposed, though the practical attack surface is limited to those who open PDFs from untrusted sources. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days (8th percentile).
· Adobe Acrobat Reader (including Acrobat Reader DC per ZDI-26-669)mass
Use-After-Free in Adobe Acrobat Reader Font Parsing Leaks Sensitive Memory
Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) in its font-parsing code that can expose sensitive contents of process memory. An attacker triggers it by crafting a malicious file (e.g., a PDF with specially formed font data) that a victim must open, so exploitation requires user interaction. Successful exploitation results in disclosure of sensitive information from memory, with no direct impact on data integrity or system availability, and the CVSS score of 5.5 (medium) reflects this read-only, local attack vector. Anyone running Adobe Acrobat Reader could be affected if they open an attacker-supplied file. As of now there is no known exploitation in the wild, no public proof-of-concept, and the EPSS probability of exploitation within 30 days is low at 0.2%; the flaw is also not in CISA's KEV catalog.
· Adobe Acrobat Reader (including Acrobat Reader DC)mass
Integer Underflow Information Disclosure in Adobe Acrobat Reader
Adobe Acrobat Reader contains an integer underflow (wrap or wraparound) flaw, CWE-191, that occurs during PDF file parsing and can lead to the disclosure of sensitive memory. The vulnerability is triggered when a victim opens a maliciously crafted PDF file, making user interaction a required part of any attack. An attacker who successfully exploits it can read sensitive information from the application's memory, which could expose data in the affected process and potentially aid further attacks; the flaw does not by itself allow code execution. Anyone running the affected versions of Acrobat Reader (identified in related coverage as Acrobat Reader DC) who opens PDFs from untrusted sources is exposed. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.2% probability of exploitation within 30 days, so no active exploitation is known.
· Adobe Acrobat Reader (Acrobat Reader DC)mass