VYPR
advisoryPublished Sep 10, 2026· 1 source

Adobe Acrobat Pro DC Vulnerable to Information Disclosure via Doc Object Flaw

A critical out-of-bounds read vulnerability in Adobe Acrobat Pro DC allows remote attackers to disclose sensitive information on affected systems.

Zero Day Initiative (ZDI) has disclosed a critical information disclosure vulnerability affecting Adobe Acrobat Pro DC. The flaw, tracked as ZDI-26-670 and assigned CVE-2026-81991, resides within the software's handling of Doc objects.

This vulnerability stems from an improper validation of user-supplied data, leading to a read operation that extends beyond the boundaries of an allocated buffer. Successful exploitation of this out-of-bounds read could allow a remote attacker to gain access to sensitive information residing on the vulnerable system. While the vulnerability itself is an information disclosure flaw, it could potentially be chained with other vulnerabilities to achieve arbitrary code execution within the context of the affected process.

Exploitation of this vulnerability requires a degree of user interaction. Attackers must trick a user into visiting a specially crafted malicious webpage or opening a malicious file. This social engineering vector is common for vulnerabilities affecting document processing software, as it relies on the user to initiate the interaction that triggers the flaw.

The Common Vulnerability Scoring System (CVSS) has assigned this vulnerability a base score of 3.3, categorizing it as low severity for the information disclosure aspect. However, the potential for chaining with other vulnerabilities to achieve code execution elevates the overall risk profile for organizations.

Adobe has acknowledged the vulnerability and has released a security update to address the issue. Users of Adobe Acrobat Pro DC are strongly advised to apply the latest patches as soon as possible to mitigate the risk of exploitation. The vendor's security advisory, APSB26-141, provides further details on the affected versions and the remediation steps.

The disclosure timeline indicates that the vulnerability was initially reported to Adobe on June 2, 2026. Following a coordinated disclosure process, ZDI publicly released their advisory on September 10, 2026, the same day the advisory was updated. The vulnerability was reported by an anonymous researcher.

This disclosure adds to a growing list of vulnerabilities affecting Adobe products, particularly within their PDF reader and authoring software. Organizations that handle sensitive documents or rely heavily on Adobe's suite for document processing should maintain a vigilant patching schedule and implement robust security practices to defend against such threats.

While the CVSS score for this specific vulnerability is low, the potential for it to be used as a stepping stone in a larger attack chain underscores the importance of timely patching and layered security defenses. Staying informed about vendor advisories and proactively applying security updates remains a cornerstone of effective cybersecurity hygiene.

Synthesized by Vypr AI