ZDI-26-668: Adobe Acrobat Reader DC Annotation Use‑After‑Free Information Disclosure (CVE‑2026‑81984)
What It Is — Adobe Acrobat Reader DC contains a use‑after‑free flaw in the handling of Annotation objects. An attacker who convinces a user to open a crafted PDF or visit a malicious page can cause the application to read memory that may contain sensitive data.
Exploitability — Requires user interaction; no public exploit code is known. CVSS 3.3 (Low‑Moderate) reflects the limited remote‑only impact but acknowledges the confidentiality loss.
Affected Products — Adobe Acrobat Reader DC (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a vulnerability‑remediation control that can be continuously monitored and evidenced for audit purposes.
- Timely patch deployment provides defensible proof of due‑diligence, a key trust signal for enterprise buyers.
- Mapping remediation to a single control objective satisfies multiple frameworks (e.g., NIST CSF, ISO 27001) simultaneously, simplifying compliance reporting.
Recommended Actions
- Deploy Adobe’s September 2026 security update on all endpoints running Acrobat Reader DC.
- Verify patch status through automated inventory or endpoint‑management tools and retain evidence of remediation.
- Incorporate the patch‑verification step into your vulnerability‑management workflow to ensure future updates are tracked and auditable.