ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-81981, an out-of-bounds write in Adobe Acrobat Reader DC annotation handling that permits remote code execution.
Zero Day Initiative advisory ZDI-26-674 details an out-of-bounds write in the annotation handling of Adobe Acrobat Reader DC. Successful exploitation allows arbitrary code execution after the victim opens a malicious file or visits a malicious page. The advisory carries a CVSS score of 7.8. No exploitation is reported.
- CVE-2026-81981 assigned; CVSS 7.8
- Out-of-bounds write in Acrobat Reader DC annotations
- User interaction required; no exploitation reported
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81981 | Out-of-Bounds Write Leading to Arbitrary Code Execution in Adobe Acrobat Reader CVE-2026-81981 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. It is triggered by user interaction: the victim must open a maliciously crafted PDF file, typically delivered via phishing or another social-engineering channel. An attacker who succeeds gains code execution in the user's context, with high impact on confidentiality, integrity, and availability, though not elevated (admin) privileges. Anyone running an affected build of Acrobat Reader is exposed; the source data does not specify affected version ranges. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (6th percentile), so no exploitation is known at this time. Do: Update Acrobat Reader to the latest patched release per Adobe's security advisory (fixed build numbers are not included in this data), and verify installed versions on endpoints to prioritize patching. Until systems are patched, keep Protected Mode/Protected View sandboxing enabled and warn users not to open unsolicited or unexpected PDF attachments, since exploitation requires the victim to open a malicious file. No public PoC or confirmed in-the-wild exploitation is known, and the 30-day exploitation probability (EPSS) is low at 0.2%, but patching should still be treated as routine-high priority given the product's ubiquity. | 7.8 | <1% |
| masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF viewer) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.
This source does not provide full text. Read it at zerodayinitiative.com.