ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 19 sources: “ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC” — merged summary and timeline →

ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 35CVE-2026-79909
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-79909, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC rated CVSS 7.8, requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-665 for a use-after-free vulnerability in Adobe Acrobat Reader DC's Annots processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-79909.

  • Use-after-free in Acrobat Reader DC annotation handling allows arbitrary remote code execution.
  • Exploitation requires the target to open a malicious file or visit a malicious page.
  • No exploitation in the wild is reported in the advisory.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-79909
Use-After-Free Code Execution Flaw in Adobe Acrobat Reader

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. The flaw is triggered locally when a victim opens a maliciously crafted PDF file, so the attack vector requires user interaction rather than network-reachable exploitation. A successful attacker gains the privileges of the user running Reader, which typically means access to that user's files and session on the workstation. All users of the affected Acrobat Reader builds are potentially exposed, as the data does not enumerate specific version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and its EPSS score of 0.2% (6th percentile) indicates a low near-term likelihood of exploitation in the wild.

Do: Monitor Adobe's Security Bulletins (APSB advisories) for this CVE and apply the patched Reader build via Adobe's updater as soon as it is released, since the data does not yet list fixed versions. In the interim, warn users not to open PDF attachments or downloads from untrusted senders, as exploitation requires opening a malicious file. Verify deployed Reader versions across your estate using software inventory so you can prioritize patching once Adobe publishes the fixed releases.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Reader is the world's dominant PDF viewer)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-79909.

This source does not provide full text. Read it at zerodayinitiative.com.