HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium Vulnerability

Information Disclosure in Adobe Acrobat Reader DC (CVE-2026-80160) JPEG2000 Parsing Out‑Of‑Bounds Read

Adobe Acrobat Reader DC contains a JPEG2000 parsing flaw (CVE‑2026‑80160) that can leak memory contents when a user opens a malicious file. The issue underscores the need for timely patching and documented remediation for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Information Disclosure in Adobe Acrobat Reader DC (CVE‑2026‑80160) JPEG2000 Parsing Out‑Of‑Bounds Read

What It Is — Adobe Acrobat Reader DC contains an out‑of‑bounds read in its JPEG2000 file parser that can leak memory contents. The flaw is catalogued as CVE‑2026‑80160.

Exploitability — An attacker must convince a user to open a crafted JPEG2000 file or visit a malicious web page. No public exploit code is known; CVSS 3.3 (Low impact).

Affected Products — Adobe Acrobat Reader DC (all supported versions released before the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Patch management is a fundamental control objective; unpatched Reader installations constitute a measurable compliance gap.
  • Continuous inventory and version‑monitoring give defensible evidence that the organization maintains a hardened software base.
  • Documented remediation provides a clear audit trail for frameworks that require proof of vulnerability‑remediation processes.

Recommended Actions — Apply Adobe’s September 2026 security update immediately, verify deployment across all endpoints with automated inventory tools, and record the remediation steps in your control‑evidence repository. Source: Adobe Security Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-659/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →