Information Disclosure in Adobe Acrobat Reader DC (CVE‑2026‑80160) JPEG2000 Parsing Out‑Of‑Bounds Read
What It Is — Adobe Acrobat Reader DC contains an out‑of‑bounds read in its JPEG2000 file parser that can leak memory contents. The flaw is catalogued as CVE‑2026‑80160.
Exploitability — An attacker must convince a user to open a crafted JPEG2000 file or visit a malicious web page. No public exploit code is known; CVSS 3.3 (Low impact).
Affected Products — Adobe Acrobat Reader DC (all supported versions released before the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Patch management is a fundamental control objective; unpatched Reader installations constitute a measurable compliance gap.
- Continuous inventory and version‑monitoring give defensible evidence that the organization maintains a hardened software base.
- Documented remediation provides a clear audit trail for frameworks that require proof of vulnerability‑remediation processes.
Recommended Actions — Apply Adobe’s September 2026 security update immediately, verify deployment across all endpoints with automated inventory tools, and record the remediation steps in your control‑evidence repository. Source: Adobe Security Advisory