CVE-2026-82001: Acrobat Reader | Uncontrolled Resource Consumption (CWE-400)
Published Sep 8, 2026
·Updated
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
6 affected components
Acrobat Reader
All of the following
Any of the following
Adobe Acrobat>=24.0.0<24.001.30429
Adobe Acrobat DC>=15.008.20082<26.002.21901
Adobe Acrobat Reader DC>=15.008.20082<26.002.21901
Any of the following
Apple macOS
Microsoft Windows
Event History
Sep 8, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What must an attacker do to trigger the denial of service?
The attacker must provide a malicious file and persuade the victim to open it in Acrobat Reader. The vulnerability has local attack vector and requires user interaction.
2
What is the expected impact if exploitation succeeds?
Successful exploitation can exhaust system resources and cause Acrobat Reader to become unavailable. The provided impact information indicates availability impact only, with no stated confidentiality or integrity impact.