Description
Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Update Software
AI Analysis

Impact

This vulnerability is an integer underflow (wrap or wraparound) that allows an attacker to access sensitive memory areas, potentially exposing confidential data. The flaw arises when an operation does not properly check the bounds of an input value, causing arithmetic calculations to wrap around and read unintended memory. The result can be a disclosure of arbitrary information stored in memory, which is a confidentiality risk and consistent with CWE-191.

Affected Systems

Affected systems include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. The CVE data lists these vendors and products but does not specify particular patches or versions, so users should verify the presence of the fix in their installed software.

Risk and Exploitability

The CVSS score is 5.5, indicating a medium severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious PDF file. Therefore the attack vector is file-based and depends on the victim's careful handling of attachments. Given the moderate CVSS rating, the likelihood of exploitation appears limited, though the vulnerability remains exploitable if the target’s environment permits loading of compromised PDFs.

Generated by OpenCVE AI on September 9, 2026 at 09:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Acrobat Reader or Adobe Acrobat releases that include the patch for the integer underflow vulnerability.
  • Configure Adobe Acrobat to automatically download and install security updates to ensure timely protection.
  • Verify that all PDF attachments are scanned by antivirus or endpoint protection before opening, and avoid opening unknown files from untrusted sources.

Generated by OpenCVE AI on September 9, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Integer Underflow (Wrap or Wraparound) (CWE-191)
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:29:09.423Z

Reserved: 2026-08-27T21:20:45.364Z

Link: CVE-2026-81977

cve-icon Vulnrichment

Updated: 2026-09-11T21:29:04.714Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:44.137

Modified: 2026-09-11T22:16:44.233

Link: CVE-2026-81977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:00:09Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)