ZDI publishes 10 CVSS 7.8 remote code execution advisories for Adobe Acrobat Reader DC and Acrobat Pro DC
On 2026-09-10 the Zero Day Initiative published ten advisories (ZDI-26-658, -661, -662, -663, -664, -665, -667, -671, -675, -676) for ten distinct CVSS 7.8 remote code execution vulnerabilities in Adobe Acrobat Reader DC and Pro DC: eight use-after-free bugs,…
On 2026-09-10 (advisory timestamp 2026-09-10T05:00:00Z), the Zero Day Initiative published ten advisories covering ten distinct remote code execution vulnerabilities in Adobe Acrobat Reader DC and Acrobat Pro DC, all rated CVSS 7.8: ZDI-26-658, ZDI-26-661, ZDI-26-662, ZDI-26-663, ZDI-26-664, ZDI-26-665, ZDI-26-667, ZDI-26-671, ZDI-26-675 and ZDI-26-676. Eight are use-after-free flaws: six in Acrobat Reader DC annotation/Annots handling (CVE-2026-79909/ZDI-26-665, CVE-2026-81985/ZDI-26-661, CVE-2026-81990/ZDI-26-662, CVE-2026-81975/ZDI-26-667, CVE-2026-81986/ZDI-26-664 and CVE-2026-81976/ZDI-26-675), one in Acrobat Pro DC annotation handling (CVE-2026-81989/ZDI-26-663) and one in Acrobat Reader DC DigSig (digital signature) processing (CVE-2026-81973/ZDI-26-676). The remaining two are a Dialog object type confusion in Acrobat Reader DC (CVE-2026-80161/ZDI-26-671) and an integer overflow in Acrobat Pro DC's parsing of JPEG files (CVE-2026-81987/ZDI-26-658). Successful exploitation of any of the ten allows arbitrary code execution on affected installations but requires user interaction: the target must open a malicious file or visit a malicious page. The advisories for ZDI-26-663, -664, -665, -675 and -676 state that no in-the-wild exploitation is reported, and ZDI-26-671 does not report active exploitation; the advisories for CVE-2026-81975 (ZDI-26-667), CVE-2026-81985 (ZDI-26-661), CVE-2026-81990 (ZDI-26-662) and CVE-2026-81987 (ZDI-26-658) do not state whether exploitation has been observed. The reports do not specify affected or fixed software versions or patch availability.
- On 2026-09-10 (timestamp 2026-09-10T05:00:00Z), ZDI published ten advisories (ZDI-26-658, -661, -662, -663, -664, -665, -667, -671, -675, -676) covering ten distinct CVSS 7.8 remote code execution vulnerabilities in Adobe Acrobat Reader DC…
- Eight use-after-free flaws: six in Reader DC annotation/Annots handling (CVE-2026-79909/ZDI-26-665, CVE-2026-81985/ZDI-26-661, CVE-2026-81990/ZDI-26-662, CVE-2026-81975/ZDI-26-667, CVE-2026-81986/ZDI-26-664, CVE-2026-81976/ZDI-26-675), one…
- One Dialog object type confusion in Reader DC (CVE-2026-80161/ZDI-26-671) and one integer overflow in Pro DC JPEG parsing (CVE-2026-81987/ZDI-26-658).
- All ten flaws are rated CVSS 7.8 and enable arbitrary remote code execution on affected installations.
- All ten require user interaction: the target must open a malicious file or visit a malicious page.
- No in-the-wild exploitation is reported in ZDI-26-663, -664, -665, -675 and -676; ZDI-26-671 does not report active exploitation; the advisories for CVE-2026-81975, CVE-2026-81985, CVE-2026-81990 and CVE-2026-81987 (ZDI-26-658, -661, -662,…
- Eight of the advisories concern Acrobat Reader DC and two (ZDI-26-658 and ZDI-26-663) concern Acrobat Pro DC.
- Affected or fixed software versions and patch availability are not specified in the reports.
Coverage timelineoldest first · each row is one article
- · 5d agoZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 25
ZDI discloses CVE-2026-81990, a use-after-free in Adobe Acrobat Reader DC annotation handling allowing remote code execution with CVSS 7.8.
- · 5d agoZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 40
ZDI disclosed a CVSS 7.8 use-after-free remote code execution flaw (CVE-2026-81976) in Adobe Acrobat Reader DC triggered via malicious PDFs.
- · 5d agoZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI Published Advisories· 22
ZDI disclosed CVE-2026-81981, an out-of-bounds write in Adobe Acrobat Reader DC annotation handling that permits remote code execution.
- · 5d agoZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 35
ZDI disclosed CVE-2026-79909, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC rated CVSS 7.8, requiring user interaction.
- · 5d agoZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
ZDI Published Advisories· 15
ZDI advisory ZDI-26-668 reports an annotation use-after-free (CVE-2026-81984) causing information disclosure in Adobe Acrobat Reader DC.
- · 5d agoZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 35
ZDI disclosed CVE-2026-81986, a use-after-free remote code execution flaw in Adobe Acrobat Reader DC annotation handling rated CVSS 7.8.
- · 5d agoZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 25
ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.
- · 5d agoZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 15
ZDI advisory ZDI-26-666 details an out-of-bounds read (CVE-2026-79910) when Adobe Acrobat Reader DC parses JPEG2000 files.
- · 5d agoZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 30
ZDI disclosed an annotation use-after-free RCE (CVE-2026-81975, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction.
- · 5d agoZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 15
ZDI advisory ZDI-26-669 details an out-of-bounds read (CVE-2026-81978) when Adobe Acrobat Reader DC parses JBIG2 files.
- · 5d agoZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability
ZDI Published Advisories· 30
ZDI disclosed a type confusion RCE (CVE-2026-80161, CVSS 7.8) in Adobe Acrobat Reader DC requiring user interaction to exploit.
- · 5d agoZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability
ZDI Published Advisories· 12
ZDI disclosed CVE-2026-81977, an integer underflow in Adobe Acrobat Reader DC PDF parsing that enables sensitive information disclosure.
- · 5d agoZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 22
ZDI disclosed CVE-2026-81988, a use-after-free in Adobe Acrobat Pro DC document object handling that enables remote code execution.
- · 5d agoZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 12
ZDI discloses CVE-2026-80160, an out-of-bounds read in Adobe Acrobat Reader DC JPEG2000 parsing enabling sensitive information disclosure with CVSS 3.3.
- · 5d agoZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
ZDI Published Advisories· 12
ZDI discloses CVE-2026-80162, a font-parsing use-after-free in Adobe Acrobat Reader DC enabling limited sensitive information disclosure with CVSS 3.3.
- · 5d agoZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 22
ZDI disclosed CVE-2026-81973, a use-after-free in Adobe Acrobat Reader DC digital signature handling that enables remote code execution.
- · 5d agoZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability
ZDI Published Advisories· 25
ZDI discloses CVE-2026-81987, an integer overflow in Adobe Acrobat Pro DC JPEG parsing enabling remote code execution with CVSS 7.8.
- · 5d agoZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 15
ZDI published advisory ZDI-26-670 for an out-of-bounds read information disclosure flaw (CVE-2026-81991) in Adobe Acrobat Pro DC.
- · 5d agoZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI Published Advisories· 35
ZDI disclosed CVE-2026-81989, a use-after-free remote code execution flaw in Adobe Acrobat Pro DC annotation handling rated CVSS 7.8.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81975 | Use-After-Free in Adobe Acrobat Reader Allows Arbitrary Code Execution Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the currently logged-in user. Triggering the flaw requires user interaction: an attacker must persuade a victim to open a maliciously crafted file, such as a PDF. A successful exploit could let an attacker run code with the victim's privileges, potentially enabling data theft, malware installation, or further lateral movement on the machine. All users of the affected Acrobat Reader versions who open files from untrusted sources are at risk. As of now, there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%, indicating limited near-term exploitation risk. Do: Check Adobe's security bulletin for CVE-2026-81975 to identify the fixed release and update Acrobat Reader as soon as a patch is available. In the interim, warn users not to open PDFs or other documents from untrusted senders, and consider disabling automatic PDF preview/attachment opening in email clients. Because this is a client-side flaw, endpoint patching coverage is the primary mitigation; verify your software inventory for Acrobat Reader installations across endpoints. | 7.8 | <1% |
| masshundreds of millions of users (Acrobat Reader is the default PDF reader on a large share of the world's Windows and macOS desktops) |