ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.
The Zero Day Initiative published ZDI-26-661 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the flaw CVSS 7.8 and assigned CVE-2026-81985.