ZeroHour
ZDI Published Advisoriespublished ()ingested 1
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 40CVE-2026-81976
AI summary · glm-5.3-flash

ZDI disclosed a CVSS 7.8 use-after-free remote code execution flaw (CVE-2026-81976) in Adobe Acrobat Reader DC triggered via malicious PDFs.

The Zero Day Initiative published advisory ZDI-26-675 describing a use-after-free remote code execution vulnerability in Adobe Acrobat Reader DC, tracked as CVE-2026-81976 with a CVSS 7.8 score. The flaw resides in the annotation feature. Exploitation requires user interaction: the target must visit a malicious page or open a malicious file. The advisory reports no evidence of in-the-wild exploitation.

  • Use-after-free in Adobe Acrobat Reader DC annotation handling allows remote code execution.
  • CVSS 7.8; requires the victim to visit a malicious page or open a malicious file.
  • Disclosed via ZDI; no in-the-wild exploitation reported.
VendorsAdobe
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81976
Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution

Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted PDF file, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the logged-in user who opened the file, potentially allowing malware installation or data theft on that endpoint. Anyone running an affected version of Acrobat Reader is exposed, and because Reader is opened on untrusted PDFs from email and the web, attack surface is broad despite the local attack vector. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

Do: Check Adobe's security bulletin for this CVE and update Acrobat Reader to the patched version it specifies for your platform. In the interim, warn users not to open PDFs from untrusted sources and consider blocking or sandboxing PDF attachments at the email gateway. Verify endpoint inventories for out-of-date Reader installations and confirm post-update that the fix is deployed.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (global installed base of Acrobat Reader)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81976.

This source does not provide full text. Read it at zerodayinitiative.com.