Description
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Acrobat Reader contains a Use After Free flaw that allows an attacker to execute arbitrary code in the context of the current user. The vulnerability is triggered when a malicious PDF file is opened, leading the program to reference freed memory and grant the attacker the ability to inject and run code.

Affected Systems

Adobe Acrobat 2024, Adobe Acrobat Reader and Adobe Acrobat are affected. Users running any of these versions must verify their installed version and apply the available fix.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and while EPSS is not published, the requirement for user interaction limits the attack surface to social engineering or malicious files. The flaw is not listed in CISA KEV and no public exploits are reported, but the impact of arbitrary code execution warrants prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe’s official patch from APSB26-141 to update Acrobat Reader to the latest release
  • If a patch is unavailable for legacy releases, upgrade to Acrobat 2024 or a later version that includes the fix
  • Configure Acrobat Reader to operate in a sandbox or disable automatic opening of PDF files to mitigate potential exploitation until a patch is applied

Generated by OpenCVE AI on September 9, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Use After Free (CWE-416)
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Acrobat Acrobat Dc Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:41.267Z

Reserved: 2026-08-27T21:20:45.364Z

Link: CVE-2026-81976

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:17.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:44.020

Modified: 2026-09-10T15:09:44.143

Link: CVE-2026-81976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:30:14Z

Weaknesses