ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-81986, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC annotation handling rated CVSS 7.8.
The Zero Day Initiative published advisory ZDI-26-664 for a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation processing. Successful exploitation allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 7.8 and is tracked as CVE-2026-81986.