ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.
The Zero Day Initiative published ZDI-26-661 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the flaw CVSS 7.8 and assigned CVE-2026-81985.
- Use-after-free in annotation handling enables remote code execution in Acrobat Reader DC
- Exploitation requires user interaction, such as opening a malicious file or page
- Rated CVSS 7.8 and tracked as CVE-2026-81985
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81985 | Use-After-Free in Adobe Acrobat Reader Allows Code Execution When Opening Files Adobe Acrobat Reader contains a use-after-free memory-corruption flaw (CWE-416) that can be triggered when the application processes a maliciously crafted file. Exploitation requires user interaction: the victim must open the malicious file, making this a local attack vector in which the user's own privileges are at stake. A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity and availability of that user's environment. Any user running Adobe Acrobat Reader is potentially affected; the available data does not specify which version ranges are impacted, so consult Adobe's security advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS assigns just a 0.2% probability of exploitation within 30 days (10th percentile), indicating low near-term exploitation risk. Do: Update Acrobat Reader to the latest release per Adobe's security bulletin for this CVE — the provided data lacks fixed version numbers, so verify the exact affected and patched builds there. Until patched, avoid opening PDFs and other documents from untrusted sources, and consider sandboxing or restricting Acrobat for email-delivered files. With no public PoC and low EPSS, immediate risk is low, but patching should not be deferred given the near-universal deployment base. | 7.8 | <1% |
| mass≈1 billion+ users (Acrobat Reader is the dominant desktop PDF reader) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81985.
This source does not provide full text. Read it at zerodayinitiative.com.