Junglewise Threat Intelligence

CVE-2026-81979: Adobe Acrobat Reader out-of-bounds write arbitrary code execution

CVE-2026-81979 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Adobe Acrobat, Apple macOS, Microsoft Windows, Adobe Acrobat Reader, Adobe Acrobat Dc, Adobe Acrobat Reader Dc. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Acrobat Reader contains an out-of-bounds write vulnerability that allows an attacker to execute arbitrary code with the privileges of the user running the application. An attacker can exploit this by crafting a malicious PDF file and tricking a user into opening it, leading to potential data theft, system compromise, or further malware infection.

Technical details

Acrobat Reader contains an out-of-bounds write vulnerability in PDF handling code that permits memory corruption during the processing of maliciously crafted PDF files. The vulnerability requires user interaction—a victim must open a specially crafted PDF document for the flaw to be triggered. Successful exploitation allows an attacker to write data beyond allocated buffer boundaries, overwriting adjacent memory and achieving arbitrary code execution in the context of the user running Acrobat Reader. No evidence of active exploitation in the wild has been reported at this time.

Affected products

  • Adobe Acrobat Reader

Timeline

  • 2026-09-08: disclosed

References

Related threats