HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium Vulnerability

Out-of-Bounds Read in Adobe Acrobat Reader DC (CVE-2026-79910) Enables Information Disclosure

Adobe Acrobat Reader DC contains a JPEG2000 parsing flaw (CVE‑2026‑79910) that can disclose memory contents when a user opens a malicious file. The issue highlights the need for rapid third‑party patch management to satisfy audit and control‑assurance requirements.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Out-of-Bounds Read in Adobe Acrobat Reader DC (CVE-2026-79910) Enables Information Disclosure

What It Is — A buffer‑read error in the JPEG2000 parser of Adobe Acrobat Reader DC can allow a remote attacker who convinces a user to open a crafted file or visit a malicious page to read memory beyond the allocated buffer, exposing potentially sensitive data.

Exploitability — Requires user interaction; no public exploit code; CVSS 3.3 (Low‑moderate).

Affected Products — Adobe Acrobat Reader DC (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Timely patching of third‑party software satisfies a core control objective that maps to many frameworks (e.g., NIST CSF Identify‑Protect, ISO 27001 A.12.6).
  • Recording remediation evidence creates a defensible audit trail that enterprise buyers increasingly demand.
  • Continuous monitoring of vendor advisories shortens the window of exposure for information‑disclosure risks.

Recommended Actions

  1. Deploy Adobe’s September 2026 security update on every endpoint.
  2. Verify the installed version with automated inventory tools and log the remediation in your change‑management system.
  3. If patching cannot be completed immediately, disable JPEG2000 handling as a temporary mitigation.
  4. Update your vulnerability‑management dashboard to reflect the closed finding and retain the advisory as audit evidence.

Source: Zero Day Initiative Advisory (ZDI‑26‑666)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-666/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →