ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI advisory ZDI-26-666 details an out-of-bounds read (CVE-2026-79910) when Adobe Acrobat Reader DC parses JPEG2000 files.
The Zero Day Initiative published advisory ZDI-26-666 for an out-of-bounds read triggered when Acrobat Reader DC parses JPEG2000 files. Successful exploitation allows a remote attacker to disclose sensitive information from affected installations. User interaction is required, such as opening a malicious file or visiting a malicious page. ZDI rated the issue 3.3 and assigned CVE-2026-79910.
- Out-of-bounds read occurs during JPEG2000 file parsing in Acrobat Reader DC
- Flaw enables information disclosure but requires user interaction
- ZDI assigned CVSS 3.3 and CVE-2026-79910
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-79910 | Out-of-bounds read in Adobe Acrobat Reader JPEG2000 parsing leaks sensitive memory CVE-2026-79910 is an out-of-bounds read (CWE-125) in the JPEG2000 file-parsing code of Adobe Acrobat Reader DC, which allows the application to read beyond the intended memory boundary when processing a crafted file. It is triggered when a victim opens a malicious file, most plausibly a PDF containing malformed JPEG2000 (JPX) image data, so user interaction is required (CVSS UI:R, local attack vector, scored 5.5 medium). A successful attack yields disclosure of sensitive process memory (high confidentiality impact, no integrity or availability impact); it is an information-disclosure flaw, not code execution. Anyone running an affected desktop build of Acrobat Reader is potentially exposed, though only when opening attacker-supplied files. There is currently no known exploitation, no public proof of concept, the EPSS probability is low (0.2% in 30 days, 7th percentile), and it is not in CISA KEV. Do: Update Acrobat/Reader to the patched build cited for CVE-2026-79910 in Adobe's security bulletin, using Help > Check for Updates or the installer from the bulletin, and verify the installed version afterwards. Until patched, be cautious with PDFs from untrusted sources and keep Reader's Protected Mode/Enhanced Security enabled, since the flaw only leaks memory when a victim opens a crafted file. Because only affected parsing code is involved and there is no known exploitation, this is a routine patch-cycle priority rather than an emergency. | 5.5 | <1% |
| mass≈100M+ desktop installations (Reader is the world's dominant PDF viewer) |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-79910.
This source does not provide full text. Read it at zerodayinitiative.com.