ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-81989, a use-after-free remote code execution flaw in Adobe Acrobat Pro DC annotation handling rated CVSS 7.8.
The Zero Day Initiative published advisory ZDI-26-663 for a use-after-free vulnerability in Adobe Acrobat Pro DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81989.
- Use-after-free in Acrobat Pro DC annotation handling allows arbitrary remote code execution.
- Exploitation requires the target to open a malicious file or visit a malicious page.
- No exploitation in the wild is reported in the advisory.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81989 | Use-After-Free Arbitrary Code Execution in Adobe Acrobat Reader Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-corruption bug that can be leveraged for arbitrary code execution in the context of the current user. The flaw is triggered only with user interaction: the victim must open a malicious file, most plausibly a crafted PDF, making this a client-side, socially engineered attack rather than a remote, server-side one. A successful exploit lets an attacker run code with the victim's privileges, enabling data theft, malware installation, or further movement within the environment. Anyone running the affected Acrobat Reader releases is exposed, though the source data does not enumerate specific version ranges. There is currently no sign of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.2% probability of exploitation within 30 days (10th percentile). Do: Apply the fix as soon as Adobe's advisory for CVE-2026-81989 identifies it, prioritizing endpoints that routinely open PDFs from untrusted sources; consult the Adobe bulletin for the exact patched versions. In the interim, attachment sandboxing, mail filtering, and user caution with unsolicited PDFs reduce practical risk because exploitation requires opening a malicious file. Since there is no public PoC and no KEV listing, this can be handled through the normal patch cycle rather than as an emergency. | 7.8 | <1% |
| masson the order of hundreds of millions of users (Acrobat Reader is the dominant desktop PDF viewer) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81989.
This source does not provide full text. Read it at zerodayinitiative.com.