VYPR
advisoryPublished Sep 10, 2026· 1 source

Adobe Acrobat Reader DC Font Parsing Vulnerability Allows Information Disclosure

A use-after-free vulnerability in Adobe Acrobat Reader DC's font parsing component enables remote attackers to disclose sensitive information, requiring user interaction.

Zero Day Initiative (ZDI) has disclosed a new information disclosure vulnerability affecting Adobe Acrobat Reader DC. The flaw, tracked as CVE-2026-80162, resides within the application's font parsing component and is categorized as a use-after-free issue.

Successful exploitation of this vulnerability requires a user to interact with a malicious element, such as visiting a compromised webpage or opening a specially crafted file. Once triggered, the vulnerability allows remote attackers to gain access to sensitive information on the affected system. The specific technical mechanism involves the application failing to validate the existence of an object before performing operations on it, leading to the information disclosure.

While the primary impact is information disclosure, the advisory notes that this vulnerability could potentially be leveraged in conjunction with other security flaws to achieve arbitrary code execution within the context of the current process. This highlights the potential for chained exploits to escalate the severity of the initial vulnerability.

The Common Vulnerability Scoring System (CVSS) rating for this vulnerability is 3.3, indicating a low severity for standalone exploitation but underscoring the risk when combined with other weaknesses. Adobe has acknowledged the vulnerability and has released a security update to address it.

Adobe's security bulletin APSB26-141 provides further details on the patch and affected versions. The disclosure timeline indicates that the vulnerability was reported to Adobe on July 22, 2026, and the coordinated public release of the advisory occurred on September 10, 2026, with an update to the advisory on the same day.

The vulnerability was discovered and reported by NURIHAN KIM (HanTul). This disclosure adds to the ongoing stream of vulnerabilities found in widely used software, emphasizing the continuous need for users to keep their applications updated to protect against potential threats.

Users of Adobe Acrobat Reader DC are strongly advised to apply the latest security updates provided by Adobe as soon as possible to mitigate the risk associated with CVE-2026-80162. Prompt patching is crucial to prevent potential information breaches and to close the door on exploitation pathways that could lead to more severe security incidents.

Synthesized by Vypr AI