ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-81988, a use-after-free in Adobe Acrobat Pro DC document object handling that enables remote code execution.
Zero Day Initiative advisory ZDI-26-673 describes a use-after-free vulnerability in the document object handling of Adobe Acrobat Pro DC. Arbitrary code execution is possible when a target opens a malicious file or visits a malicious page. The flaw received a CVSS rating of 7.8. No in-the-wild exploitation is reported.
- CVE-2026-81988 assigned; CVSS 7.8
- Use-after-free in Acrobat Pro DC document objects
- User interaction required; no exploitation reported
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81988 | Use-After-Free in Adobe Acrobat Reader Enables Arbitrary Code Execution Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-reuse flaw that, when successfully exploited, allows arbitrary code execution in the context of the current user. The flaw is triggered by user interaction: a victim must open a maliciously crafted file (typically a PDF) with an affected version of Reader. A successful attacker gains code execution with the victim's user privileges, enough to run malware, steal files, or pivot on the workstation, though no privilege escalation beyond the current user is implied. Everyone running a vulnerable build of Acrobat Reader is affected; given the product's ubiquity on enterprise and consumer desktops, the exposed population is very large, and exact affected version ranges should be taken from Adobe's security bulletin. There is no known public proof of concept, the issue is not on CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so exploitation status is currently none known. Do: Upgrade Acrobat Reader to the fixed release identified in Adobe's security bulletin (no specific fixed version is included in this data), using Reader's built-in updater or enterprise deployment tooling and verifying the installed version via Help > About. Until patched, discourage opening PDFs from untrusted sources and apply email gateway filtering of attachments. No public PoC or in-the-wild exploitation is known, so standard patch-cycle timelines are defensible, though high-volume PDF-handling users should be prioritized. | 7.8 | <1% |
| masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader, with 1B+ cumulative installs) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.
This source does not provide full text. Read it at zerodayinitiative.com.