Junglewise Threat Intelligence

CVE-2026-81983: Adobe Acrobat Reader out-of-bounds write vulnerability

CVE-2026-81983 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Adobe Acrobat, Apple macOS, Microsoft Windows, Adobe Acrobat Reader, Adobe Acrobat Dc, Adobe Acrobat Reader Dc. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Acrobat Reader contains an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a specially crafted PDF file. An attacker can exploit this by sending a malicious document to a user, gaining the ability to execute code with the privileges of the person viewing the PDF. This represents a significant risk to users handling untrusted documents.

Technical details

The vulnerability is an out-of-bounds write flaw in Adobe Acrobat Reader's PDF parsing or rendering component. Exploitation requires user interaction—specifically, a victim must open a malicious PDF file—but no authentication or elevated privileges are required. A successful exploit allows an attacker to achieve arbitrary code execution in the context of the current user, potentially leading to data theft, malware installation, or lateral movement within a network. Patches are expected to be released through Adobe's security update process.

Affected products

  • Adobe Acrobat Reader

Timeline

  • 2026-09-08: disclosed

References

Related threats