ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 22CVE-2026-81973
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-81973, a use-after-free in Adobe Acrobat Reader DC digital signature handling that enables remote code execution.

Zero Day Initiative advisory ZDI-26-676 describes a use-after-free vulnerability in the DigSig (digital signature) feature of Adobe Acrobat Reader DC. Exploitation requires the target to open a malicious file or visit a malicious page, after which arbitrary code can execute. The flaw carries a CVSS score of 7.8. No in-the-wild exploitation is reported.

  • CVE-2026-81973 assigned; CVSS 7.8
  • Use-after-free in Acrobat Reader DC digital signature processing
  • User interaction required for code execution

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81973
Use-After-Free Code Execution Flaw in Adobe Acrobat Reader

Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that an attacker can leverage for arbitrary code execution. The flaw is triggered when a victim opens a maliciously crafted file, such as a booby-trapped PDF, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the currently logged-in user, which could allow installation of malware, data theft, or further lateral movement on the workstation. Anyone running an affected release of Adobe Acrobat Reader is exposed; the source data does not enumerate specific affected version ranges, so defenders should consult Adobe's security bulletin (APSB) for exact versions and platforms. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only about 0.2%.

Do: Check installed Acrobat Reader versions in your estate and apply Adobe's patched release as soon as it is available per the Adobe security bulletin (APSB) referenced in the advisory, since the source data does not list fixed build numbers. Until patched, caution users against opening PDFs from untrusted or unexpected sources, as exploitation requires a victim to open a malicious file. No public exploit exists yet and EPSS is low, so treat this as a routine patch-cycle priority rather than an emergency, but verify completion once updates ship.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of desktop installations worldwide
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.

This source does not provide full text. Read it at zerodayinitiative.com.