Junglewise Threat Intelligence

CVE-2026-81973: Adobe Acrobat Reader use-after-free vulnerability

CVE-2026-81973 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Adobe Acrobat, Apple macOS, Microsoft Windows, Adobe Acrobat Reader, Adobe Acrobat Dc, Adobe Acrobat Reader Dc. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Acrobat Reader contains a use-after-free vulnerability that could allow arbitrary code execution when a user opens a malicious PDF file. An attacker can exploit this flaw to run malicious code with the privileges of the affected user, potentially compromising sensitive documents, stealing data, or installing malware on systems relying on Acrobat Reader for document processing.

Technical details

This is a use-after-free vulnerability in Adobe Acrobat Reader's memory handling logic. The vulnerability occurs when the application attempts to access or manipulate memory that has already been freed, allowing an attacker to corrupt memory state and achieve arbitrary code execution. Exploitation requires user interaction—specifically, the victim must open a specially crafted malicious PDF file. The attack vector is local, requiring no network connectivity or elevated privileges prior to exploitation. No patch availability information is publicly available at this time.

Affected products

  • Adobe Acrobat Reader <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats