Skip to content
AdobeCVE-2026-81994

Adobe Acrobat 2024: prototype pollution

High8.2CVE-2026-81994 · Published Sep 8, 2026 · updated Sep 10, 2026

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Adobe advisory

Affected versions

PackageAffectedFixed in
Acrobat 2024
Product
<= 24.001.30383No fix yet
Acrobat Reader
Product
<= 26.002.21900No fix yet
Adobe Acrobat
Product
<= 26.002.21900No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1321

More Adobe advisories

All Adobe
Advisory
Adobe Acrobat 2024: heap buffer overflow
Medium5.5Sep 8
Adobe Acrobat 2024: improper authorization
High8.8Sep 8
Adobe Acrobat 2024: improper authorization
Medium6.3Sep 8
Adobe Acrobat 2024: resource exhaustion
Medium5.5Sep 8
Adobe Acrobat 2024: use after free
High7.8Sep 8
Adobe Acrobat 2024: use after free
High7.8Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.