Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-81997
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2026-81997 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Acrobat and Acrobat Reader that allows a local attacker to bypass security features and gain unauthorized write access. Disclosed on September 8, 2026, it affects Adobe Acrobat and Acrobat Reader (Continuous track) versions 26.002.21900 and earlier, and Acrobat 2024 versions 24.001.30383 and earlier, on both Windows and macOS. Exploitation requires a victim to open a malicious PDF file. The vulnerability carries a CVSS v3.1 base score of 6.3 (Medium) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to correctly perform authorization checks when an actor attempts to access a resource or perform an action. The attack vector is local, requiring low complexity and no privileges, but does require user interaction — specifically, a victim must open a crafted malicious PDF file. When exploited, the scope changes beyond the vulnerable component, enabling unauthorized write access to resources outside the normal security boundary of Acrobat Reader (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to bypass security measures enforced by Adobe Acrobat Reader and gain unauthorized write access to files or system resources, with a high integrity impact and a changed scope. Confidentiality and availability are not directly impacted by this vulnerability. The scope change indicates that the impact can extend beyond the Acrobat Reader process itself to affect other components or files on the system (Adobe Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Adobe Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.152% (0.00162), placing it in the 5th percentile for exploitation likelihood within 30 days. Exploitation is not automatable and requires user interaction, reducing the overall risk of widespread exploitation (GitHub Advisory).

Exploitation steps

  1. Craft a malicious PDF: An attacker creates a specially crafted PDF file designed to trigger the incorrect authorization check within Adobe Acrobat Reader when opened.
  2. Deliver the malicious file: The attacker delivers the PDF to a target via phishing email, malicious download link, or other social engineering means.
  3. Victim opens the file: The victim opens the malicious PDF using a vulnerable version of Adobe Acrobat or Acrobat Reader (≤26.002.21900 or Acrobat 2024 ≤24.001.30383).
  4. Authorization bypass triggered: The malicious PDF triggers the flawed authorization logic, causing Acrobat Reader to bypass security feature checks.
  5. Unauthorized write access achieved: The attacker's payload gains write access to files or resources outside the normal security scope of the Acrobat Reader process, potentially modifying system or user files (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected file modifications in directories not normally writable by the Acrobat Reader process; new or altered files created at the time a PDF was opened.
  • Process: Adobe Acrobat Reader process (AcroRd32.exe or Acrobat.exe) performing unusual file write operations outside its standard working directories.
  • Logs: System audit logs showing file write events initiated by the Acrobat Reader process to sensitive or unexpected locations coinciding with PDF file open events.
  • Network: Outbound connections from the Acrobat Reader process to unknown external hosts shortly after opening a PDF (may indicate secondary payload delivery if chained with other vulnerabilities).

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Acrobat and Acrobat Reader (Continuous) version 26.002.21901 or later, and Acrobat 2024 version 24.001.30429 or later. Users should update to the latest available version via Adobe's update mechanism or by downloading directly from Adobe. As a precautionary measure, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider implementing application whitelisting or restricting PDF macro/JavaScript execution where policy permits (Adobe Advisory).

Community reactions

The vulnerability was noted in the context of Adobe's September 2026 patch release, which addressed multiple products. The CIS Security advisory flagged the broader Adobe September 2026 update as addressing vulnerabilities that could allow for arbitrary code execution across multiple Adobe products. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-81997 has been identified beyond standard vulnerability tracking and aggregation sites.

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81996HIGH8.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc
NoYesSep 08, 2026
CVE-2026-81997MEDIUM6.3
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesSep 08, 2026
CVE-2026-81994MEDIUM6.3
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc
NoYesSep 08, 2026
CVE-2026-82001MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
NoYesSep 08, 2026
CVE-2026-81993MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management