Description
Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Acrobat Reader is affected by an integer overflow or wraparound vulnerability that could result in arbitrary code execution in the context of the current user. The flaw occurs when processing a maliciously crafted file, and the vulnerability may be triggered when a user opens that file.

Affected Systems

Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat are the affected products.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Exploitation requires user interaction, specifically opening a malicious file. Thus the attack surface is limited to users who inadvertently open such files, but the risk remains high until the vendor patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 09:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat Reader patch released by Adobe on the security bulletin.
  • Ensure automatic updates are enabled so future patches are received promptly.
  • Avoid opening PDF files from unknown or untrusted sources until the patch is installed.

Generated by OpenCVE AI on September 9, 2026 at 09:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T13:07:15.394Z

Reserved: 2026-08-27T21:20:45.366Z

Link: CVE-2026-81987

cve-icon Vulnrichment

Updated: 2026-09-10T13:00:49.823Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:45.343

Modified: 2026-09-10T15:57:13.127

Link: CVE-2026-81987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:21Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound