ZeroHour
Story · 1 source · 19 articlesfirst updated ()

ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC

What's new: Relative to the previous story summary (ten advisories from ZDI-26-661 to ZDI-26-676, with nine CVSS 7.8 RCE flaws and one CVSS 3.3 out-of-bounds read), this merge covers a revised set of ten advisories: ZDI-26-658, -661, -662, -663, -664, -665, -667, -671, -675 and -676. Newly included are ZDI-26-658 (CVE-2026-81987, integer overflow in Acrobat Pro DC JPEG parsing) and ZDI-26-663…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-10 the Zero Day Initiative published ten advisories (ZDI-26-658, -661, -662, -663, -664, -665, -667, -671, -675, -676) for ten distinct CVSS 7.8 remote code execution vulnerabilities in Adobe Acrobat Reader DC and Pro DC: eight use-after-free bugs,…

On 2026-09-10 (advisory timestamp 2026-09-10T05:00:00Z), the Zero Day Initiative published ten advisories covering ten distinct remote code execution vulnerabilities in Adobe Acrobat Reader DC and Acrobat Pro DC, all rated CVSS 7.8: ZDI-26-658, ZDI-26-661, ZDI-26-662, ZDI-26-663, ZDI-26-664, ZDI-26-665, ZDI-26-667, ZDI-26-671, ZDI-26-675 and ZDI-26-676. Eight are use-after-free flaws: six in Acrobat Reader DC annotation/Annots handling (CVE-2026-79909/ZDI-26-665, CVE-2026-81985/ZDI-26-661, CVE-2026-81990/ZDI-26-662, CVE-2026-81975/ZDI-26-667, CVE-2026-81986/ZDI-26-664 and CVE-2026-81976/ZDI-26-675), one in Acrobat Pro DC annotation handling (CVE-2026-81989/ZDI-26-663) and one in Acrobat Reader DC DigSig (digital signature) processing (CVE-2026-81973/ZDI-26-676). The remaining two are a Dialog object type confusion in Acrobat Reader DC (CVE-2026-80161/ZDI-26-671) and an integer overflow in Acrobat Pro DC's parsing of JPEG files (CVE-2026-81987/ZDI-26-658). Successful exploitation of any of the ten allows arbitrary code execution on affected installations but requires user interaction: the target must open a malicious file or visit a malicious page. The advisories for ZDI-26-663, -664, -665, -675 and -676 state that no in-the-wild exploitation is reported, and ZDI-26-671 does not report active exploitation; the advisories for CVE-2026-81975 (ZDI-26-667), CVE-2026-81985 (ZDI-26-661), CVE-2026-81990 (ZDI-26-662) and CVE-2026-81987 (ZDI-26-658) do not state whether exploitation has been observed. The reports do not specify affected or fixed software versions or patch availability.

  • On 2026-09-10 (timestamp 2026-09-10T05:00:00Z), ZDI published ten advisories (ZDI-26-658, -661, -662, -663, -664, -665, -667, -671, -675, -676) covering ten distinct CVSS 7.8 remote code execution vulnerabilities in Adobe Acrobat Reader DC…
  • Eight use-after-free flaws: six in Reader DC annotation/Annots handling (CVE-2026-79909/ZDI-26-665, CVE-2026-81985/ZDI-26-661, CVE-2026-81990/ZDI-26-662, CVE-2026-81975/ZDI-26-667, CVE-2026-81986/ZDI-26-664, CVE-2026-81976/ZDI-26-675), one…
  • One Dialog object type confusion in Reader DC (CVE-2026-80161/ZDI-26-671) and one integer overflow in Pro DC JPEG parsing (CVE-2026-81987/ZDI-26-658).
  • All ten flaws are rated CVSS 7.8 and enable arbitrary remote code execution on affected installations.
  • All ten require user interaction: the target must open a malicious file or visit a malicious page.
  • No in-the-wild exploitation is reported in ZDI-26-663, -664, -665, -675 and -676; ZDI-26-671 does not report active exploitation; the advisories for CVE-2026-81975, CVE-2026-81985, CVE-2026-81990 and CVE-2026-81987 (ZDI-26-658, -661, -662,…
  • Eight of the advisories concern Acrobat Reader DC and two (ZDI-26-658 and ZDI-26-663) concern Acrobat Pro DC.
  • Affected or fixed software versions and patch availability are not specified in the reports.

Coverage timeline

  1. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    ZDI discloses CVE-2026-81990, a use-after-free in Adobe Acrobat Reader DC annotation handling allowing remote code execution with CVSS 7.8.

  2. · 5d ago
    ZDI Published Advisories· 40
    ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed a CVSS 7.8 use-after-free remote code execution flaw (CVE-2026-81976) in Adobe Acrobat Reader DC triggered via malicious PDFs.

  3. · 5d ago
    ZDI Published Advisories· 22
    ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-81981, an out-of-bounds write in Adobe Acrobat Reader DC annotation handling that permits remote code execution.

  4. · 5d ago
    ZDI Published Advisories· 35
    ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-79909, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC rated CVSS 7.8, requiring user interaction.

  5. · 5d ago
    ZDI Published Advisories· 15
    ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

    ZDI advisory ZDI-26-668 reports an annotation use-after-free (CVE-2026-81984) causing information disclosure in Adobe Acrobat Reader DC.

  6. · 5d ago
    ZDI Published Advisories· 35
    ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-81986, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC annotation handling rated CVSS 7.8.

  7. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.

  8. · 5d ago
    ZDI Published Advisories· 15
    ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI advisory ZDI-26-666 details an out-of-bounds read (CVE-2026-79910) when Adobe Acrobat Reader DC parses JPEG2000 files.

  9. · 5d ago
    ZDI Published Advisories· 30
    ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.

  10. · 5d ago
    ZDI Published Advisories· 15
    ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI advisory ZDI-26-669 details an out-of-bounds read (CVE-2026-81978) when Adobe Acrobat Reader DC parses JBIG2 files.

  11. · 5d ago
    ZDI Published Advisories· 30
    ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

    ZDI disclosed a type confusion RCE (CVE-2026-80161, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction to exploit.

  12. · 5d ago
    ZDI Published Advisories· 12
    ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability

    ZDI disclosed CVE-2026-81977, an integer underflow in Adobe Acrobat Reader DC PDF parsing that enables sensitive information disclosure.

  13. · 5d ago
    ZDI Published Advisories· 22
    ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-81988, a use-after-free in Adobe Acrobat Pro DC document object handling that enables remote code execution.

  14. · 5d ago
    ZDI Published Advisories· 12
    ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI discloses CVE-2026-80160, an out-of-bounds read in Adobe Acrobat Reader DC JPEG2000 parsing enabling sensitive information disclosure with CVSS 3.3.

  15. · 5d ago
    ZDI Published Advisories· 12
    ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

    ZDI discloses CVE-2026-80162, a font-parsing use-after-free in Adobe Acrobat Reader DC enabling limited sensitive information disclosure with CVSS 3.3.

  16. · 5d ago
    ZDI Published Advisories· 22
    ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-81973, a use-after-free in Adobe Acrobat Reader DC digital signature handling that enables remote code execution.

  17. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

    ZDI discloses CVE-2026-81987, an integer overflow in Adobe Acrobat Pro DC JPEG parsing enabling remote code execution with CVSS 7.8.

  18. · 5d ago
    ZDI Published Advisories· 15
    ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI published advisory ZDI-26-670 for an out-of-bounds read information disclosure flaw (CVE-2026-81991) in Adobe Acrobat Pro DC.

  19. · 5d ago
    ZDI Published Advisories· 35
    ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-81989, a use-after-free remote code execution flaw in Adobe Acrobat Pro DC annotation handling rated CVSS 7.8.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81975
Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk.

Do: Check Adobe's security bulletin for CVE-2026-81975 to identify the fixed release and update Acrobat Reader as soon as a patch is available. In the interim, warn users not to open PDFs or other documents from untrusted senders, and consider disabling automatic PDF preview/attachment opening in email clients. Because this is a client-side flaw, endpoint patching coverage is the primary mitigation; verify your software inventory for Acrobat Reader installations across endpoints.

7.8<1%
  • Adobe Acrobat Reader
masshundreds of millions of users (Acrobat Reader is the default PDF reader on a large share of the world's Windows and macOS desktops)