ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
ZDI discloses CVE-2026-80162, a font-parsing use-after-free in Adobe Acrobat Reader DC enabling limited sensitive information disclosure with CVSS 3.3.
The Zero Day Initiative published ZDI-26-660 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's font parsing. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80162.