Executive brief
Adobe Acrobat Reader, a widely used application for viewing and editing PDF documents, is vulnerable to a denial-of-service attack through uncontrolled resource consumption. An attacker can craft a malicious PDF file that, when opened by a user, exhausts system resources and crashes the application, disrupting work and potentially affecting broader system stability.
Technical details
This is an uncontrolled resource consumption vulnerability (CWE-400 or similar) in Adobe Acrobat Reader's PDF parsing engine. The vulnerability is triggered when a victim opens a specially crafted malicious PDF file, causing the application to consume excessive system resources (CPU, memory, or disk I/O). The attack requires user interaction—the victim must be tricked into opening the malicious file—and does not provide remote code execution or data exfiltration. A patch is expected to be available via Adobe's security bulletin APSB26-141.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed