ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

mediumAdvisoryimportance 25CVE-2026-81990
AI summary · glm-5.3-flash

ZDI discloses CVE-2026-81990, a use-after-free in Adobe Acrobat Reader DC annotation handling allowing remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-662 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Successful exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned a CVSS score of 7.8 and tracked the flaw as CVE-2026-81990.

  • Use-after-free in annotation handling enables remote code execution in Acrobat Reader DC
  • Exploitation requires user interaction, such as opening a malicious file or page
  • Rated CVSS 7.8 and tracked as CVE-2026-81990

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81990
Use-After-Free Code Execution Flaw in Adobe Acrobat Reader

Adobe Acrobat Reader contains a use-after-free (CWE-416) memory corruption vulnerability that can allow arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted file, most plausibly a PDF, making user interaction a required part of any attack. An attacker who successfully exploits it gains code execution under the victim's account, with high confidentiality, integrity and availability impact, though they do not gain privileges beyond that user. Anyone running a vulnerable version of Acrobat Reader is affected, including typical desktop and enterprise deployments of the widely used PDF viewer. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation within 30 days.

Do: Apply Adobe's patched release for CVE-2026-81990 as soon as it is available, checking installed Acrobat Reader versions against the fixed versions listed in Adobe's advisory. Until patched, instruct users not to open PDFs or other files from untrusted sources, as exploitation requires opening a malicious file. Given the very low EPSS and absence of public exploits, routine patch-cycle remediation is reasonable for most environments.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Acrobat Reader is the world's dominant desktop PDF viewer, deployed on the vast majority of Windows and macOS endpoints)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81990.

This source does not provide full text. Read it at zerodayinitiative.com.