ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.
The Zero Day Initiative published advisory ZDI-26-667 for a use-after-free vulnerability in the annotation feature of Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when the user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-81975. The advisory does not state whether exploitation has been observed.
- Use-after-free in annotation handling enables arbitrary code execution in Acrobat Reader DC
- Exploitation requires the target to open a malicious file or page
- ZDI assigned CVSS 7.8 and CVE-2026-81975
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81975 | Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk. Do: Check Adobe's security bulletin for CVE-2026-81975 to identify the fixed release and update Acrobat Reader as soon as a patch is available. In the interim, warn users not to open PDFs or other documents from untrusted senders, and consider disabling automatic PDF preview/attachment opening in email clients. Because this is a client-side flaw, endpoint patching coverage is the primary mitigation; verify your software inventory for Acrobat Reader installations across endpoints. | 7.8 | <1% |
| masshundreds of millions of users (Acrobat Reader is the default PDF reader on a large share of the world's Windows and macOS desktops) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81975.
This source does not provide full text. Read it at zerodayinitiative.com.