ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.
The Zero Day Initiative published advisory ZDI-26-667 for a use-after-free vulnerability in the annotation feature of Adobe Acrobat Reader DC. The flaw allows remote attackers to execute arbitrary code when the user opens a malicious file or visits a malicious page. ZDI rated the issue 7.8 on the CVSS scale and assigned CVE-2026-81975. The advisory does not state whether exploitation has been observed.