CVE-2026-79909: Acrobat Reader | Use After Free (CWE-416)
Published Sep 8, 2026
·Updated
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Acrobat Reader
Event History
Sep 8, 2026
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Acrobat Reader users are exposed if they open a malicious file. Successful exploitation runs code in the context of the current user.
2
What does an attacker need to exploit it?
An attacker must persuade or otherwise cause a victim to open a malicious file. The provided information does not indicate any additional authentication or privilege requirement.
3
Does exploitation require user interaction?
Yes. A victim must open a malicious file for exploitation to occur.