Junglewise Threat Intelligence

CVE-2026-81977: Adobe Acrobat Reader integer underflow in memory handling

CVE-2026-81977 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Adobe Acrobat, Apple macOS, Microsoft Windows, Adobe Acrobat Reader, Adobe Acrobat Dc, Adobe Acrobat Reader Dc. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Acrobat Reader contains an integer underflow vulnerability in its memory handling logic that could allow an attacker to disclose sensitive information from system memory. This vulnerability requires a user to open a malicious PDF file, making it a practical attack vector against organizations that exchange documents. Successful exploitation could expose confidential data stored in memory at the time of the attack.

Technical details

An integer underflow (wrap or wraparound) vulnerability exists in Adobe Acrobat Reader's memory processing logic. The vulnerability occurs when an integer value wraps around during arithmetic operations, causing the application to allocate or access memory incorrectly. This flaw requires user interaction—specifically, opening a specially crafted malicious PDF file—to trigger the vulnerability. An attacker can exploit this to read sensitive information from process memory. No publicly known fix is available at this time based on the advisory information provided.

Affected products

  • Adobe Acrobat Reader <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats