Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

zetlyn/cve-nvd vulnerability cve CVE-2026-81987 cpe cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* cpe cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* cpe cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* cpe cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* known 2026-09-08

https://nvd.nist.gov/vuln/detail/CVE-2026-81987

Properties

cvss7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Adobe Acrobat",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat Reader",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat 2024",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "24.001.30383",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "24.001.30429",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
                "matchCriteriaId": "A6C6B745-7D94-43D9-BD26-1B26EE34DED4",
                "versionEndExcluding": "24.001.30429",
                "versionStartIncluding": "24.001.20604",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "B9192F4D-A119-46C4-A167-F500ACB3ACAB",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "2FEAAE8A-F164-4DCA-8F08-9BC646831744",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-81987",
    "lastModified": "2026-09-10T15:57:13.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-81987",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T03:55:19.966750Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T21:18:45.343",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/acrobat/apsb26-141.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
productAdobe Acrobat
receipt
Source
NVD
Its words
Adobe Acrobat
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCAdobe Acrobat
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Adobe Acrobat",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat Reader",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat 2024",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "24.001.30383",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "24.001.30429",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
                "matchCriteriaId": "A6C6B745-7D94-43D9-BD26-1B26EE34DED4",
                "versionEndExcluding": "24.001.30429",
                "versionStartIncluding": "24.001.20604",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "B9192F4D-A119-46C4-A167-F500ACB3ACAB",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "2FEAAE8A-F164-4DCA-8F08-9BC646831744",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-81987",
    "lastModified": "2026-09-10T15:57:13.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-81987",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T03:55:19.966750Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T21:18:45.343",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/acrobat/apsb26-141.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
statusAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Adobe Acrobat",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat Reader",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat 2024",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "24.001.30383",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "24.001.30429",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
                "matchCriteriaId": "A6C6B745-7D94-43D9-BD26-1B26EE34DED4",
                "versionEndExcluding": "24.001.30429",
                "versionStartIncluding": "24.001.20604",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "B9192F4D-A119-46C4-A167-F500ACB3ACAB",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "2FEAAE8A-F164-4DCA-8F08-9BC646831744",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-81987",
    "lastModified": "2026-09-10T15:57:13.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-81987",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T03:55:19.966750Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T21:18:45.343",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/acrobat/apsb26-141.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
vendorAdobe
receipt
Source
NVD
Its words
Adobe
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCAdobe
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Adobe Acrobat",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat Reader",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.002.21900",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "26.002.21901",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Acrobat 2024",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "24.001.30383",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "24.001.30429",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
                "matchCriteriaId": "A6C6B745-7D94-43D9-BD26-1B26EE34DED4",
                "versionEndExcluding": "24.001.30429",
                "versionStartIncluding": "24.001.20604",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "B9192F4D-A119-46C4-A167-F500ACB3ACAB",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
                "matchCriteriaId": "2FEAAE8A-F164-4DCA-8F08-9BC646831744",
                "versionEndExcluding": "26.002.21901",
                "versionStartIncluding": "15.008.20082",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-81987",
    "lastModified": "2026-09-10T15:57:13.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-81987",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T03:55:19.966750Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T21:18:45.343",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/acrobat/apsb26-141.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}

Text

Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.