ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

lowAdvisoryimportance 12CVE-2026-80160
AI summary · glm-5.3-flash

ZDI discloses CVE-2026-80160, an out-of-bounds read in Adobe Acrobat Reader DC JPEG2000 parsing enabling sensitive information disclosure with CVSS 3.3.

The Zero Day Initiative published ZDI-26-659 covering an out-of-bounds read in Adobe Acrobat Reader DC's parsing of JPEG2000 files. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80160.

  • Out-of-bounds read in JPEG2000 parsing allows information disclosure
  • Requires user interaction, such as opening a crafted file
  • Rated CVSS 3.3 and tracked as CVE-2026-80160

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-80160
Out-of-Bounds Read in Adobe Acrobat Reader JPEG2000 Parsing Leaks Sensitive Memory

Adobe Acrobat Reader is affected by an out-of-bounds read vulnerability (CWE-125) in its parsing of JPEG2000 image data, per the ZDI advisory (ZDI-26-659), which could allow disclosure of sensitive memory contents. The flaw is triggered when a victim opens a maliciously crafted file, meaning user interaction is required for exploitation. A successful attack results in information disclosure (high confidentiality impact, no integrity or availability impact), and the local attack vector and user interaction requirement cap the CVSS 3.1 score at 5.5 (medium). All users running affected versions of Acrobat Reader are potentially exposed. As of now there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

Do: Update Acrobat Reader to the patched release identified in Adobe's security bulletin for this CVE (no fixed version number is provided in the source data); confirm the installed version via Help > About and update via Help > Check for Updates. Because exploitation requires opening a malicious file, users should avoid opening PDFs from untrusted sources until patched. No public PoC or in-the-wild exploitation is known, so this can be handled through routine patch cycles rather than emergency response.

5.5<1%
  • Adobe Acrobat Reader DC (Acrobat Reader)
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader)
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.

This source does not provide full text. Read it at zerodayinitiative.com.