Description
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out-of-bounds write that can allow an attacker to execute arbitrary code in the context of the user who opens a malicious file. This flaw is identified as CWE-787, indicating a failure to properly check bounds before performing a memory write. If exploited, the attacker could gain full control over the victim’s system, tampering with data or installing malicious software.

Affected Systems

Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat products are affected. The advisory does not list specific patch versions; organizations should verify that their installations are at least at the latest release for each of these products.

Risk and Exploitability

The CVSS score of 7.8 places this flaw in the high‑severity range, while the EPSS score is not available, suggesting no publicly available exploitation data as of the latest update. The vulnerability requires user interaction—the victim must open a crafted PDF file. This limits attack surface to scenarios where malicious documents are delivered via email, web, or other media. Without such interaction, the flaw cannot be triggered, reducing the likelihood of opportunistic exploitation.

Generated by OpenCVE AI on September 9, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat Reader update from the vendor’s official website.
  • Avoid opening PDFs or other files from unknown or untrusted sources until a patch is applied.
  • Configure Acrobat Reader to disable JavaScript and enable its sandbox feature to limit the effect of any future exploitation.

Generated by OpenCVE AI on September 9, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:41.585Z

Reserved: 2026-08-27T21:20:45.365Z

Link: CVE-2026-81979

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:21.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:44.387

Modified: 2026-09-10T15:04:35.417

Link: CVE-2026-81979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T04:45:18Z

Weaknesses