ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 22CVE-2026-81988
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-81988, a use-after-free in Adobe Acrobat Pro DC document object handling that enables remote code execution.

Zero Day Initiative advisory ZDI-26-673 describes a use-after-free vulnerability in the document object handling of Adobe Acrobat Pro DC. Arbitrary code execution is possible when a target opens a malicious file or visits a malicious page. The flaw received a CVSS rating of 7.8. No in-the-wild exploitation is reported.

  • CVE-2026-81988 assigned; CVSS 7.8
  • Use-after-free in Acrobat Pro DC document objects
  • User interaction required; no exploitation reported

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81988
Use-After-Free in Adobe Acrobat Reader Enables Arbitrary Code Execution

Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-reuse flaw that, when successfully exploited, allows arbitrary code execution in the context of the current user. The flaw is triggered by user interaction: a victim must open a maliciously crafted file (typically a PDF) with an affected version of Reader. A successful attacker gains code execution with the victim's user privileges, enough to run malware, steal files, or pivot on the workstation, though no privilege escalation beyond the current user is implied. Everyone running a vulnerable build of Acrobat Reader is affected; given the product's ubiquity on enterprise and consumer desktops, the exposed population is very large, and exact affected version ranges should be taken from Adobe's security bulletin. There is no known public proof of concept, the issue is not on CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so exploitation status is currently none known.

Do: Upgrade Acrobat Reader to the fixed release identified in Adobe's security bulletin (no specific fixed version is included in this data), using Reader's built-in updater or enterprise deployment tooling and verifying the installed version via Help > About. Until patched, discourage opening PDFs from untrusted sources and apply email gateway filtering of attachments. No public PoC or in-the-wild exploitation is known, so standard patch-cycle timelines are defensible, though high-volume PDF-handling users should be prioritized.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader, with 1B+ cumulative installs)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.

This source does not provide full text. Read it at zerodayinitiative.com.