HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Use‑After‑Free Information Disclosure in Adobe Acrobat Reader DC (CVE‑2026‑80162)

Adobe Acrobat Reader DC has a use‑after‑free bug (CVE‑2026‑80162) that can leak memory contents when a crafted PDF is opened. The flaw underscores the importance of continuous vulnerability scanning and timely patching to maintain audit‑ready evidence of secure configurations.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free Information Disclosure in Adobe Acrobat Reader DC (CVE‑2026‑80162)

What It Is — Adobe Acrobat Reader DC contains a use‑after‑free flaw in its font‑parsing code that can be triggered by a malicious PDF or web page. The bug allows a remote attacker to read memory contents from the victim process, potentially exposing sensitive information.

Exploitability — The vulnerability requires user interaction (opening a crafted file or visiting a malicious page). No public exploit code is known, and the CVSS base score is 3.3 (Low‑Moderate).

Affected Products — Adobe Acrobat Reader DC (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – Demonstrates the need for continuous scanning and rapid patch deployment to satisfy the control objective of maintaining a secure configuration.
  • Audit Evidence – Timely remediation provides defensible proof for auditors that the organization monitors and mitigates known flaws.
  • Supply‑Chain Trust – End‑user applications are a common attack surface; maintaining up‑to‑date software is a core trust signal for enterprise buyers.

Recommended Actions

  • Identify all endpoints running Adobe Acrobat Reader DC and verify their version.
  • Deploy Adobe’s September 2026 security update (APS‑B26‑141) across the environment.
  • Record patch‑deployment evidence in your vulnerability‑management system to map the remediation to the relevant control objective.
  • Review your patch‑management policy to ensure user‑initiated software (e.g., PDF readers) is included in regular scanning cycles.

Source: Zero Day Initiative Advisory ZDI‑26‑660

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-660/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →