VYPR
patchPublished Sep 10, 2026· 11 sources

Adobe Acrobat Reader DC Vulnerability Allows Remote Code Execution via Annotation Flaw

A critical use-after-free vulnerability in Adobe Acrobat Reader DC, tracked as CVE-2026-81976, enables remote code execution with a CVSS score of 7.8.

Zero Day Initiative (ZDI) has disclosed a critical use-after-free vulnerability affecting Adobe Acrobat Reader DC, identified as ZDI-26-675 and assigned the CVE identifier CVE-2026-81976. This flaw carries a significant CVSS score of 7.8, indicating a high level of risk to users.

The vulnerability resides within the application's handling of Annotation objects. Specifically, the issue arises from a failure to properly validate the existence of an object before performing operations on it. This oversight allows attackers to exploit the flaw, leading to the execution of arbitrary code on a victim's system.

To successfully exploit this vulnerability, an attacker must trick a user into interacting with malicious content. This typically involves luring the user to a compromised webpage or convincing them to open a specially crafted file. Once the user interaction occurs, the exploit can proceed, leveraging the use-after-free condition to gain control.

Successful exploitation of this vulnerability allows an attacker to execute code in the context of the current process. This means that any privileges or access the Acrobat Reader DC process has on the system could be leveraged by the attacker, potentially leading to further compromise of the user's machine or network.

Adobe has acknowledged the vulnerability and has released a security update to address it. Users are strongly advised to update their Adobe Acrobat Reader DC installations to the latest version to mitigate this risk. Further details on the patch can be found in Adobe's security advisory APSB26-141.

The vulnerability was initially reported to Adobe on June 30, 2026. Following a coordinated disclosure process, ZDI published its advisory on September 10, 2026, the same day Adobe released its fix. This timeline highlights the ongoing efforts to address security flaws in widely used software.

This disclosure underscores the persistent threat posed by vulnerabilities in popular PDF readers. Attackers frequently target these applications due to their widespread use and the potential for attackers to deliver malicious payloads through documents or web links, making them a common vector for initial compromise.

The Zero Day Initiative has released details on a new remote code execution vulnerability in Adobe Acrobat Reader DC, designated ZDI-26-671 and assigned CVE-2026-80161. This advisory details a type confusion flaw within the Dialog object, which differs from the previously reported use-after-free vulnerability (CVE-2026-81976) in the annotation component. While both require user interaction and have a CVSS score of 7.8, this new finding highlights a distinct mechanism for achieving code execution in the widely used PDF reader.

The Zero Day Initiative advisory ZDI-26-674 details CVE-2026-81981, an out-of-bounds write vulnerability in Adobe Acrobat Reader DC. This new advisory specifies that the flaw exists within the handling of Annotation objects, allowing remote attackers to execute arbitrary code by tricking users into opening malicious files or visiting malicious webpages. Adobe has released security update APSB26-141 to address this specific vulnerability.

This new advisory from Zero Day Initiative provides the specific CVE identifier, CVE-2026-79909, for the Adobe Acrobat Reader DC use-after-free vulnerability. It also details that the vulnerability exists within the handling of Report objects due to a lack of validation before object operations, allowing for code execution in the context of the current process.

The Zero Day Initiative advisory ZDI-26-664 provides further technical details on the use-after-free vulnerability in Adobe Acrobat Reader DC, identified as CVE-2026-81986. This advisory confirms that the flaw resides within the parsing of Annotation objects, stemming from insufficient validation before object operations, and requires user interaction for exploitation. Adobe has released a patch for this vulnerability, detailed in APSB26-141.

This advisory details a use-after-free vulnerability in Adobe Acrobat Reader DC's Annotation object handling, specifically related to improper object existence validation. While the previously reported CVE-2026-81976 focused on remote code execution, this new vulnerability (ZDI-26-668) is categorized as an information disclosure with a lower CVSS score of 3.3, requiring user interaction via a malicious webpage or file.

This advisory details a use-after-free vulnerability within Adobe Acrobat Reader DC's DigSig component, specifically tracked as CVE-2026-81973. While the existing story mentions a similar remote code execution flaw (CVE-2026-81976) in the Annotation component, this new report focuses on a distinct vulnerability that also requires user interaction for exploitation. Adobe has released a patch for this specific DigSig issue.

The Zero Day Initiative has published its advisory ZDI-26-667, detailing a use-after-free vulnerability in Adobe Acrobat Reader DC that allows for remote code execution. This advisory assigns the CVE identifier CVE-2026-81975 to the flaw, which differs from the CVE-2026-81976 mentioned in previous reporting, indicating a potential separate but related vulnerability or a typo in earlier disclosures. Adobe has released a patch for this specific CVE as part of APSB26-141.

The Zero Day Initiative advisory ZDI-26-661 details a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation handling, assigned CVE-2026-81985. This new advisory provides specific technical details on the vulnerability's mechanism, which involves improper validation of object existence before operations, leading to remote code execution. Adobe has released a patch for this issue as part of APSB26-141.

The Zero Day Initiative advisory ZDI-26-662 details a use-after-free vulnerability in Adobe Acrobat Reader DC, identified as CVE-2026-81990. This new advisory provides specific technical details on the flaw's mechanism, which involves improper handling of Annotation objects and a failure to validate object existence before operations. The vulnerability allows for remote code execution with a CVSS score of 7.8, requiring user interaction to exploit.

This advisory details a use-after-free vulnerability in Adobe Acrobat Pro DC, specifically impacting its annotation handling. While the previous report focused on Acrobat Reader DC, this new information highlights a similar flaw in the Pro version, also allowing for remote code execution with a CVSS score of 7.8, requiring user interaction to exploit.

Synthesized by Vypr AI