HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Information Disclosure in Adobe Acrobat Reader DC (CVE-2026-80160) JPEG2000 Parsing Out‑Of‑Bounds Read

Adobe Acrobat Reader DC contains a JPEG2000 parsing flaw (CVE‑2026‑80160) that can leak memory contents when a user opens a malicious file. The issue underscores the need for timely patching and documented remediation for audit readiness.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Information Disclosure in Adobe Acrobat Reader DC (CVE‑2026‑80160) JPEG2000 Parsing Out‑Of‑Bounds Read

What It Is — Adobe Acrobat Reader DC contains an out‑of‑bounds read in its JPEG2000 file parser that can leak memory contents. The flaw is catalogued as CVE‑2026‑80160.

Exploitability — An attacker must convince a user to open a crafted JPEG2000 file or visit a malicious web page. No public exploit code is known; CVSS 3.3 (Low impact).

Affected Products — Adobe Acrobat Reader DC (all supported versions released before the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Patch management is a fundamental control objective; unpatched Reader installations constitute a measurable compliance gap.
  • Continuous inventory and version‑monitoring give defensible evidence that the organization maintains a hardened software base.
  • Documented remediation provides a clear audit trail for frameworks that require proof of vulnerability‑remediation processes.

Recommended Actions — Apply Adobe’s September 2026 security update immediately, verify deployment across all endpoints with automated inventory tools, and record the remediation steps in your control‑evidence repository. Source: Adobe Security Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-659/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →