ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

mediumAdvisoryimportance 30CVE-2026-80161
AI summary · glm-5.3-flash

ZDI disclosed a type confusion RCE (CVE-2026-80161, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction to exploit.

The Zero Day Initiative published advisory ZDI-26-671 for a Dialog Object type confusion vulnerability in Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when a user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-80161. The advisory does not report active exploitation.

  • Type confusion in the Dialog object enables arbitrary code execution in Acrobat Reader DC
  • Exploitation requires the target to open a malicious file or visit a malicious page
  • ZDI assigned CVSS 7.8 and CVE-2026-80161

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-80161
Type Confusion Vulnerability in Adobe Acrobat Reader Allows Arbitrary Code Execution

CVE-2026-80161 is a type confusion (CWE-843) vulnerability in Adobe Acrobat Reader that occurs when the application accesses a resource using an incompatible type, potentially corrupting memory during document processing. It is triggered when a victim opens a maliciously crafted file, such as an untrusted PDF, meaning the attack requires user interaction but no special privileges or network access. A successful exploit allows the attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. All users of the affected Acrobat Reader versions identified in Adobe's advisory are exposed, and the flaw is rated High severity (CVSS 7.8). As of now there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.2% probability of exploitation in the next 30 days.

Do: Consult Adobe's security advisory for the affected version ranges and apply the patched Acrobat Reader release once published; the specific fixed versions were not included in the available data. In the interim, instruct users not to open PDFs from untrusted sources and consider blocking or sandboxing PDF attachments in email gateways and browsers. Inventory endpoints for Acrobat Reader installations to prioritize patching, since exploitation requires only a user opening one malicious file.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Acrobat Reader is the world's dominant PDF viewer)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-80161.

This source does not provide full text. Read it at zerodayinitiative.com.