ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
ZDI advisory ZDI-26-668 reports an annotation use-after-free (CVE-2026-81984) causing information disclosure in Adobe Acrobat Reader DC.
The Zero Day Initiative published advisory ZDI-26-668 for a use-after-free condition in the annotation feature of Adobe Acrobat Reader DC. Exploitation allows remote attackers to disclose sensitive information when the target opens a malicious file or page. ZDI rated the issue 3.3 on the CVSS scale and assigned CVE-2026-81984.
- Use-after-free in annotation handling enables information disclosure in Acrobat Reader DC
- Exploitation requires user interaction with attacker-supplied content
- ZDI assigned CVSS 3.3 and CVE-2026-81984
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81984 | Use-After-Free Information Disclosure in Adobe Acrobat Reader Annotation Handling Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) in its annotation processing, tracked as ZDI-26-668, that can leak sensitive memory contents. An attacker triggers the flaw by crafting a malicious PDF file and persuading a victim to open it, since exploitation requires local user interaction. Successful exploitation discloses sensitive information from memory, though it does not allow code execution or file modification. All users of Adobe Acrobat Reader who open untrusted PDF files are potentially affected, with the reader's enormous installed base making broad exposure likely. As of now there is no known public proof-of-concept, the vulnerability is not in CISA's Known Exploited Vulnerabilities catalog, and the EPSS score of 0.2% indicates low expected near-term exploitation. Do: Update Acrobat Reader to the latest release available from Adobe's security bulletin (specific patched versions are not listed in the available data, so verify against the official Adobe advisory for CVE-2026-81984). Until patched, avoid opening PDF files from untrusted or unverified sources and consider configuring Reader for Protected Mode/Protected View. Check deployed Reader versions across endpoints and prioritize patching users who regularly handle PDF attachments from external parties. | 5.5 | <1% |
| masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader worldwide) |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81984.
This source does not provide full text. Read it at zerodayinitiative.com.