ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-81973, a use-after-free in Adobe Acrobat Reader DC digital signature handling that enables remote code execution.
Zero Day Initiative advisory ZDI-26-676 describes a use-after-free vulnerability in the DigSig (digital signature) feature of Adobe Acrobat Reader DC. Exploitation requires the target to open a malicious file or visit a malicious page, after which arbitrary code can execute. The flaw carries a CVSS score of 7.8. No in-the-wild exploitation is reported.
- CVE-2026-81973 assigned; CVSS 7.8
- Use-after-free in Acrobat Reader DC digital signature processing
- User interaction required for code execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81973 | Use-After-Free Code Execution Flaw in Adobe Acrobat Reader Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that an attacker can leverage for arbitrary code execution. The flaw is triggered when a victim opens a maliciously crafted file, such as a booby-trapped PDF, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the currently logged-in user, which could allow installation of malware, data theft, or further lateral movement on the workstation. Anyone running an affected release of Adobe Acrobat Reader is exposed; the source data does not enumerate specific affected version ranges, so defenders should consult Adobe's security bulletin (APSB) for exact versions and platforms. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only about 0.2%. Do: Check installed Acrobat Reader versions in your estate and apply Adobe's patched release as soon as it is available per the Adobe security bulletin (APSB) referenced in the advisory, since the source data does not list fixed build numbers. Until patched, caution users against opening PDFs from untrusted or unexpected sources, as exploitation requires a victim to open a malicious file. No public exploit exists yet and EPSS is low, so treat this as a routine patch-cycle priority rather than an emergency, but verify completion once updates ship. | 7.8 | <1% |
| masshundreds of millions of desktop installations worldwide |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.
This source does not provide full text. Read it at zerodayinitiative.com.