ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 35CVE-2026-81986
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-81986, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC annotation handling rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-664 for a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81986.

  • Use-after-free in Acrobat Reader DC annotation handling allows arbitrary remote code execution.
  • Exploitation requires the target to open a malicious file or visit a malicious page.
  • No exploitation in the wild is reported in the advisory.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81986
Use-After-Free in Adobe Acrobat Reader Enables Code Execution via Malicious File

Adobe Acrobat Reader contains a use-after-free memory corruption flaw (CWE-416) that occurs when the application references freed memory while processing a crafted file. The bug is triggered locally when a victim opens an attacker-supplied malicious file, typically a PDF, in an affected Reader build, so no network-facing service is involved and user interaction is required. Successful exploitation allows arbitrary code execution in the context of the current user, meaning an attacker gains the victim's privileges, which can mean full account compromise if that user runs with administrator rights. Anyone running an affected version of Acrobat Reader is exposed; the source data does not enumerate specific version ranges, so defenders should check Adobe's security bulletin for the exact affected and fixed builds. Exploitation status is currently quiet: there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.

Do: Update Acrobat Reader to the fixed release identified in Adobe's security bulletin for this CVE once published, covering the Reader builds Adobe lists as affected. Until patching is complete, treat unsolicited PDFs and files from untrusted sources as suspect, since exploitation requires a victim to open the malicious file, and keep Reader's Protected Mode (sandbox) enabled to constrain any code execution. Given the low EPSS and absence of a public PoC or KEV listing, there is no current evidence of active targeting, so routine patch cadence is sufficient.

7.8<1%
  • Adobe Acrobat Reader
mass≈1 billion+ potential installations (Acrobat Reader is the dominant desktop PDF viewer)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81986.

This source does not provide full text. Read it at zerodayinitiative.com.