Description
Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Apply Updates
AI Analysis

Impact

Adobe Acrobat and Acrobat Reader contain a type confusion flaw that permits arbitrary code execution when a user opens a specially crafted file. The vulnerability can be leveraged by an attacker to run code with the privileges of the current user, potentially compromising the device and user data.

Affected Systems

Adobe releases affected by this flaw include Acrobat 2024, Acrobat Reader, and Adobe Acrobat. No specific version numbers are listed in the CNA data; all current releases are potentially vulnerable until a patch is applied.

Risk and Exploitability

The severity score of 7.8 indicates a high risk of exploitation. The EXSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to interact by opening a malicious file, making user awareness a critical defense factor. If exploited, the attacker can achieve full code execution under the victim’s user context.

Generated by OpenCVE AI on September 9, 2026 at 09:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe update that addresses the type confusion issue, as described in Adobe Security Advisory APSB26-141.
  • Enable Acrobat Reader’s high‑security mode or otherwise restrict the execution of active content to mitigate the risk of arbitrary code execution.
  • Maintain up‑to‑date anti‑malware protection and scan files before opening them to reduce the chance that a malicious document triggers the exploit.

Generated by OpenCVE AI on September 9, 2026 at 09:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T13:07:15.528Z

Reserved: 2026-08-25T20:51:11.639Z

Link: CVE-2026-80161

cve-icon Vulnrichment

Updated: 2026-09-10T13:00:51.670Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:43.213

Modified: 2026-09-10T15:56:54.100

Link: CVE-2026-80161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:27Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')