ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

lowAdvisoryimportance 12CVE-2026-80162
AI summary · glm-5.3-flash

ZDI discloses CVE-2026-80162, a font-parsing use-after-free in Adobe Acrobat Reader DC enabling limited sensitive information disclosure with CVSS 3.3.

The Zero Day Initiative published ZDI-26-660 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's font parsing. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80162.

  • Font-parsing use-after-free allows information disclosure in Acrobat Reader DC
  • Requires user interaction, such as opening a crafted file
  • Rated CVSS 3.3 and tracked as CVE-2026-80162

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-80162
Use-After-Free in Adobe Acrobat Reader Font Parsing Leaks Sensitive Memory

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) in its font-parsing code that can expose sensitive contents of process memory. An attacker triggers it by crafting a malicious file (e.g., a PDF with specially formed font data) that a victim must open, so exploitation requires user interaction. Successful exploitation results in disclosure of sensitive information from memory, with no direct impact on data integrity or system availability, and the CVSS score of 5.5 (medium) reflects this read-only, local attack vector. Anyone running Adobe Acrobat Reader could be affected if they open an attacker-supplied file. As of now there is no known exploitation in the wild, no public proof-of-concept, and the EPSS probability of exploitation within 30 days is low at 0.2%; the flaw is also not in CISA's KEV catalog.

Do: Update Acrobat Reader to the latest release per Adobe's security bulletin, since the source data does not list specific fixed version numbers. Until patched, caution users against opening PDFs from untrusted sources and keep Reader's Protected Mode/Protected View enabled to limit memory-disclosure risk. Although no exploitation is currently known, font-parsing bugs in PDF readers are a common ingredient in exploit chains, so prioritize patching on endpoints that handle untrusted documents.

5.5<1%
  • Adobe Acrobat Reader (including Acrobat Reader DC)
masshundreds of millions of potential users (Reader is one of the world's most widely installed desktop applications)
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.

This source does not provide full text. Read it at zerodayinitiative.com.