ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

mediumVulnerabilityimportance 22CVE-2026-81981
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-81981, an out-of-bounds write in Adobe Acrobat Reader DC annotation handling that permits remote code execution.

Zero Day Initiative advisory ZDI-26-674 details an out-of-bounds write in the annotation handling of Adobe Acrobat Reader DC. Successful exploitation allows arbitrary code execution after the victim opens a malicious file or visits a malicious page. The advisory carries a CVSS score of 7.8. No exploitation is reported.

  • CVE-2026-81981 assigned; CVSS 7.8
  • Out-of-bounds write in Acrobat Reader DC annotations
  • User interaction required; no exploitation reported

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81981
Out-of-Bounds Write Leading to Arbitrary Code Execution in Adobe Acrobat Reader

CVE-2026-81981 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. It is triggered by user interaction: the victim must open a maliciously crafted PDF file, typically delivered via phishing or another social-engineering channel. An attacker who succeeds gains code execution in the user's context, with high impact on confidentiality, integrity, and availability, though not elevated (admin) privileges. Anyone running an affected build of Acrobat Reader is exposed; the source data does not specify affected version ranges. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (6th percentile), so no exploitation is known at this time.

Do: Update Acrobat Reader to the latest patched release per Adobe's security advisory (fixed build numbers are not included in this data), and verify installed versions on endpoints to prioritize patching. Until systems are patched, keep Protected Mode/Protected View sandboxing enabled and warn users not to open unsolicited or unexpected PDF attachments, since exploitation requires the victim to open a malicious file. No public PoC or confirmed in-the-wild exploitation is known, and the 30-day exploitation probability (EPSS) is low at 0.2%, but patching should still be treated as routine-high priority given the product's ubiquity.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF viewer)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.

This source does not provide full text. Read it at zerodayinitiative.com.