CVE-2026-81986: Acrobat Reader | Use After Free (CWE-416)
Published Sep 8, 2026
·Updated
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
6 affected components
Adobe Acrobat Reader
All of the following
Any of the following
Adobe Acrobat>=24.001.20604<24.001.30429
Adobe Acrobat DC>=15.008.20082<26.002.21901
Adobe Acrobat Reader DC>=15.008.20082<26.002.21901
Any of the following
Apple macOS
Microsoft Windows
Event History
Sep 8, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who is exposed to this issue?
Users of Adobe Acrobat Reader are exposed when they open a malicious file. Successful exploitation can execute code with the privileges of the current user.
2
What does an attacker need to exploit it?
The attacker must get a victim to open a malicious file. The supplied data does not indicate that exploitation requires prior authentication or privileges.
3
Is user interaction required?
Yes. A victim must open the malicious file for exploitation to occur.