ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 5.5
- EPSS
- 0%
Key insight
A use-after-free vulnerability in Adobe Acrobat Reader DC enables information disclosure through malicious PDF or font files.
Description
Vulnerability CVE-2026-80162 is a use-after-free flaw in the font-parsing module of Adobe Acrobat Reader DC. Remote attackers can disclose sensitive information from affected system memory by inducing users to open malicious PDFs or visit malicious web pages. Exploitation requires user interaction. With a CVSS score of 3.3, the vulnerability is classified as low severity and is not on the CISA KEV list.
Risk score
- cvss base
- 55.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 70.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational