Junglewise Threat Intelligence

CVE-2026-81984: Adobe Acrobat Reader use after free in memory handling

CVE-2026-81984 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Adobe Acrobat Reader is widely used for viewing and managing PDF documents in enterprises and by consumers. A use-after-free vulnerability in the application's memory handling could allow an attacker to read sensitive data from the application's memory, such as passwords or documents, if a user opens a malicious PDF file.

Technical details

This vulnerability is a use-after-free (CWE-416) defect in Adobe Acrobat Reader's memory management that could allow disclosure of sensitive information from the affected process memory. The attack requires user interaction—specifically, a victim must open a specially crafted malicious PDF file to trigger the vulnerability. An attacker can exploit this flaw to leak sensitive data residing in memory at the time of exploitation. The vulnerability has been assigned CVE-2026-81984 with a CVSS score of 5.5 (medium severity). No evidence of active exploitation in the wild has been reported, and patches are expected from Adobe.

Affected products

  • Adobe Acrobat Reader <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats