ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

lowAdvisoryimportance 15CVE-2026-81978
AI summary · glm-5.3-flash

ZDI advisory ZDI-26-669 details an out-of-bounds read (CVE-2026-81978) when Adobe Acrobat Reader DC parses JBIG2 files.

The Zero Day Initiative published advisory ZDI-26-669 for an out-of-bounds read triggered when Acrobat Reader DC parses JBIG2 files. Successful exploitation allows a remote attacker to disclose sensitive information from affected installations. User interaction is required, such as opening a malicious file or visiting a malicious page. ZDI rated the issue 3.3 and assigned CVE-2026-81978.

  • Out-of-bounds read occurs during JBIG2 file parsing in Acrobat Reader DC
  • Flaw enables information disclosure but requires user interaction
  • ZDI assigned CVSS 3.3 and CVE-2026-81978

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81978
Out-of-Bounds Read in Adobe Acrobat Reader JBIG2 Parsing Leaks Sensitive Memory

Adobe Acrobat Reader (the DC variant is cited in the related ZDI-26-669 advisory) contains an out-of-bounds read (CWE-125) in its JBIG2 file parsing code that reads beyond allocated memory buffers. Exploitation requires user interaction: a victim must open a malicious PDF file for the parsing flaw to trigger. A successful attacker gains disclosure of sensitive process memory (CVSS confidentiality impact rated High), but the flaw cannot modify files or execute code, which is why the severity is Medium (5.5). Any user running an affected Acrobat Reader build is technically exposed, though the practical attack surface is limited to those who open PDFs from untrusted sources. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days (8th percentile).

Do: Install the Acrobat Reader security update referenced in Adobe's bulletin for CVE-2026-81978, verifying exact affected and patched builds there since they are not provided in this data. Until patched, caution users against opening PDFs from untrusted or unsolicited sources, and consider disabling or sandboxing JBIG2 handling where policy allows. Because the flaw requires user interaction and only discloses memory contents, treat this as a routine-patch-severity item rather than an emergency.

5.5<1%
  • Adobe Acrobat Reader (including Acrobat Reader DC per ZDI-26-669)
masshundreds of millions of users (Reader is the dominant desktop PDF viewer)
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81978.

This source does not provide full text. Read it at zerodayinitiative.com.