ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

mediumAdvisoryimportance 30CVE-2026-81975
AI summary · glm-5.3-flash

ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-667 for a use-after-free vulnerability in the annotation feature of Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when the user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-81975. The advisory does not state whether exploitation has been observed.

  • Use-after-free in annotation handling enables arbitrary code execution in Acrobat Reader DC
  • Exploitation requires the target to open a malicious file or page
  • ZDI assigned CVSS 7.8 and CVE-2026-81975

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81975
Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk.

Do: Check Adobe's security bulletin for CVE-2026-81975 to identify the fixed release and update Acrobat Reader as soon as a patch is available. In the interim, warn users not to open PDFs or other documents from untrusted senders, and consider disabling automatic PDF preview/attachment opening in email clients. Because this is a client-side flaw, endpoint patching coverage is the primary mitigation; verify your software inventory for Acrobat Reader installations across endpoints.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Acrobat Reader is the default PDF reader on a large share of the world's Windows and macOS desktops)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81975.

This source does not provide full text. Read it at zerodayinitiative.com.