ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability
ZDI disclosed CVE-2026-81977, an integer underflow in Adobe Acrobat Reader DC PDF parsing that enables sensitive information disclosure.
Zero Day Initiative advisory ZDI-26-672 reports an integer underflow in PDF file parsing in Adobe Acrobat Reader DC. A remote attacker could disclose sensitive information, but exploitation requires the victim to open a malicious file or visit a malicious page. The flaw carries a low CVSS score of 3.3. No exploitation is reported.
- CVE-2026-81977 assigned; CVSS 3.3
- Integer underflow causes information disclosure in PDF parsing
- User interaction required; low-severity issue
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81977 | Integer Underflow Information Disclosure in Adobe Acrobat Reader Adobe Acrobat Reader contains an integer underflow (wrap or wraparound) flaw, CWE-191, that occurs during PDF file parsing and can lead to the disclosure of sensitive memory. The vulnerability is triggered when a victim opens a maliciously crafted PDF file, making user interaction a required part of any attack. An attacker who successfully exploits it can read sensitive information from the application's memory, which could expose data in the affected process and potentially aid further attacks; the flaw does not by itself allow code execution. Anyone running the affected versions of Acrobat Reader (identified in related coverage as Acrobat Reader DC) who opens PDFs from untrusted sources is exposed. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.2% probability of exploitation within 30 days, so no active exploitation is known. Do: Update Acrobat Reader to the latest release using Adobe's updater or by checking Adobe's security advisory for fixed versions, since the source data does not specify affected/fixed builds. Until patched, avoid opening PDFs from untrusted or unknown sources and caution users against doing so. Given no known exploitation and a low EPSS score, patching on your normal critical-update cycle is reasonable, but prioritize systems that routinely handle external PDFs. | 5.5 | <1% |
| masshundreds of millions of potential users (Acrobat Reader is one of the most widely deployed desktop PDF viewers) |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.
This source does not provide full text. Read it at zerodayinitiative.com.