cbcvebase.
CVE-2026-81996
published 2026-09-08

CVE-2026-81996: Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this…

PriorityP350high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
3.0th percentile
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeacrobat>= 24.0.0 < 24.001.3042924.001.30429
adobeacrobat_2024<= 24.001.30383
adobeacrobat_dc>= 15.008.20082 < 26.002.2190126.002.21901
adobeacrobat_reader<= 26.002.21900
adobeacrobat_reader_dc>= 15.008.20082 < 26.002.2190126.002.21901
adobeadobe_acrobat<= 26.002.21900
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.