Junglewise Threat Intelligence

CVE-2026-81978: Adobe Acrobat Reader out-of-bounds read in PDF parsing

CVE-2026-81978 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Adobe Acrobat, Apple macOS, Microsoft Windows, Adobe Acrobat Reader, Adobe Acrobat Dc, Adobe Acrobat Reader Dc. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Acrobat Reader is widely used to view and edit PDF documents in corporate and consumer environments. This vulnerability allows an attacker to read sensitive data from the application's memory by crafting a malicious PDF file; a victim must open the file for the attack to succeed. An attacker could exploit this to extract confidential information such as passwords, encryption keys, or other sensitive data stored in memory.

Technical details

This is an out-of-bounds read vulnerability in Adobe Acrobat Reader's PDF parsing engine. The vulnerability is triggered when the application processes a specially crafted PDF file, allowing an attacker to read memory beyond allocated buffer boundaries. The attack requires user interaction—a victim must open or view a malicious PDF document. Successful exploitation can lead to information disclosure from the application's memory space. No patch details are available from the provided advisory content.

Affected products

  • Adobe Acrobat Reader <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats