Use‑After‑Free Information Disclosure in Adobe Acrobat Reader DC (CVE‑2026‑80162)
What It Is — Adobe Acrobat Reader DC contains a use‑after‑free flaw in its font‑parsing code that can be triggered by a malicious PDF or web page. The bug allows a remote attacker to read memory contents from the victim process, potentially exposing sensitive information.
Exploitability — The vulnerability requires user interaction (opening a crafted file or visiting a malicious page). No public exploit code is known, and the CVSS base score is 3.3 (Low‑Moderate).
Affected Products — Adobe Acrobat Reader DC (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Vulnerability Management – Demonstrates the need for continuous scanning and rapid patch deployment to satisfy the control objective of maintaining a secure configuration.
- Audit Evidence – Timely remediation provides defensible proof for auditors that the organization monitors and mitigates known flaws.
- Supply‑Chain Trust – End‑user applications are a common attack surface; maintaining up‑to‑date software is a core trust signal for enterprise buyers.
Recommended Actions
- Identify all endpoints running Adobe Acrobat Reader DC and verify their version.
- Deploy Adobe’s September 2026 security update (APS‑B26‑141) across the environment.
- Record patch‑deployment evidence in your vulnerability‑management system to map the remediation to the relevant control objective.
- Review your patch‑management policy to ensure user‑initiated software (e.g., PDF readers) is included in regular scanning cycles.