Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-81994
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2026-81994 is a Prototype Pollution vulnerability (CWE-1321) in Adobe Acrobat and Acrobat Reader that can lead to arbitrary file system read, allowing attackers to access sensitive files and directories outside the intended access scope. Disclosed on September 8, 2026, it affects Adobe Acrobat and Acrobat Reader versions 26.002.21900 and earlier on Windows and macOS, as well as Acrobat 2024 versions 24.001.30383 and earlier. The vulnerability carries a CVSS v3.1 base score of 6.3 (Medium) per NVD, though the GitHub Advisory Database and ENISA rate it as 8.2 (High) due to both high confidentiality and integrity impact with changed scope (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — 'Prototype Pollution'), where the application fails to properly control modifications to object prototype attributes when processing attacker-supplied input embedded in a malicious PDF or Acrobat file. By manipulating prototype attributes, an attacker can cause the application to read arbitrary files from the file system beyond the intended access scope, resulting in a scope change. Exploitation requires no special privileges but does require user interaction — specifically, a victim must open a malicious file (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to read arbitrary files and directories on the victim's file system that are outside the intended access scope of Adobe Acrobat/Reader, resulting in high confidentiality impact and, per the higher CVSS scoring, potential integrity impact as well. The changed scope indicator means the vulnerability can affect resources beyond the vulnerable component itself, potentially exposing sensitive organizational data such as credentials, configuration files, or private documents. Availability is not impacted, and no remote code execution has been attributed to this specific vulnerability (Adobe Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Adobe Advisory). The EPSS score is approximately 0.304% (23rd percentile), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Exploitation is not automatable, as it requires the victim to open a specially crafted malicious file.

Exploitation steps

  1. Craft a malicious file: Create a specially crafted PDF or Acrobat-compatible file that embeds a Prototype Pollution payload targeting Adobe Acrobat's JavaScript or object processing engine, designed to manipulate object prototype attributes to redirect file system read operations.
  2. Deliver the file: Distribute the malicious file to the target via phishing email, malicious download link, or other social engineering methods, since exploitation requires the victim to open the file.
  3. Trigger prototype pollution: When the victim opens the file in a vulnerable version of Adobe Acrobat or Acrobat Reader (≤26.002.21900 or Acrobat 2024 ≤24.001.30383), the malicious payload causes the application to improperly modify object prototype attributes.
  4. Achieve arbitrary file read: The polluted prototype causes the application to read files and directories outside the intended access scope, potentially exposing sensitive files (e.g., credentials, configuration files, private documents) on the victim's system.
  5. Exfiltrate data: Depending on the payload design, the attacker may leverage the file read capability to exfiltrate sensitive data through embedded callbacks or secondary channels (Adobe Advisory, GitHub Advisory).

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Adobe Acrobat and Acrobat Reader should be updated to version 26.002.21901 or later (Continuous track), and Acrobat 2024 should be updated to version 24.001.30429 or later. Users should apply the security update referenced in Adobe security bulletin APSB26-141 as the primary remediation. As additional hardening measures, organizations should consider implementing application whitelisting, restricting user permissions, and training users to avoid opening PDF files from untrusted sources (Adobe Advisory).

Community reactions

The vulnerability was noted by the Center for Internet Security (CIS) in an advisory covering multiple Adobe product vulnerabilities patched in September 2026. Security monitoring platforms including Tenable (Nessus plugins 343841–343844) and Qualys (detection ID 388662) added detection coverage shortly after disclosure. Social media mentions appeared on Bluesky and Mastodon, primarily from automated CVE tracking accounts, with no significant researcher commentary or public debate noted (Adobe Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81996HIGH8.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesSep 08, 2026
CVE-2026-81997MEDIUM6.3
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesSep 08, 2026
CVE-2026-81994MEDIUM6.3
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
NoYesSep 08, 2026
CVE-2026-82001MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesSep 08, 2026
CVE-2026-81993MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management