{"api_version":"1","generated_at":"2026-09-11T08:06:43+00:00","cve":"CVE-2026-81984","urls":{"html":"https://cve.report/CVE-2026-81984","api":"https://cve.report/api/cve/CVE-2026-81984.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-81984","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-81984"},"summary":{"title":"Acrobat Reader | Use After Free (CWE-416)","description":"Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.","state":"PUBLISHED","assigner":"adobe","published_at":"2026-09-08 21:18:44","updated_at":"2026-09-10 15:17:47"},"problem_types":["CWE-416","CWE-416 Use After Free (CWE-416)"],"metrics":[{"version":"3.1","source":"psirt@adobe.com","type":"Secondary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","availabilityRequirement":"NOT_DEFINED","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","confidentialityRequirement":"NOT_DEFINED","environmentalScore":5.5,"environmentalSeverity":"MEDIUM","exploitCodeMaturity":"NOT_DEFINED","integrityImpact":"NONE","integrityRequirement":"NOT_DEFINED","modifiedAttackComplexity":"LOW","modifiedAttackVector":"LOCAL","modifiedAvailabilityImpact":"NONE","modifiedConfidentialityImpact":"HIGH","modifiedIntegrityImpact":"NONE","modifiedPrivilegesRequired":"NONE","modifiedScope":"UNCHANGED","modifiedUserInteraction":"REQUIRED","privilegesRequired":"NONE","remediationLevel":"NOT_DEFINED","reportConfidence":"NOT_DEFINED","scope":"UNCHANGED","temporalScore":5.5,"temporalSeverity":"MEDIUM","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://helpx.adobe.com/security/products/acrobat/apsb26-141.html","name":"https://helpx.adobe.com/security/products/acrobat/apsb26-141.html","refsource":"psirt@adobe.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81984","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81984","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Adobe","product":"Adobe Acrobat","version":"affected 26.002.21900 custom","platforms":[]},{"source":"CNA","vendor":"Adobe","product":"Adobe Acrobat","version":"unaffected 26.002.21901 custom","platforms":[]},{"source":"CNA","vendor":"Adobe","product":"Acrobat Reader","version":"affected 26.002.21900 custom","platforms":[]},{"source":"CNA","vendor":"Adobe","product":"Acrobat Reader","version":"unaffected 26.002.21901 custom","platforms":[]},{"source":"CNA","vendor":"Adobe","product":"Acrobat 2024","version":"affected 24.001.30383 custom","platforms":[]},{"source":"CNA","vendor":"Adobe","product":"Acrobat 2024","version":"unaffected 24.001.30429 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"81984","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"classic","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"81984","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_dc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"continuous","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"81984","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_reader_dc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"continuous","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"81984","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"macos","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"81984","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"81984","cve":"CVE-2026-81984","epss":"0.001810000","percentile":"0.077490000","score_date":"2026-09-10","updated_at":"2026-09-11 00:05:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-81984","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-09T16:41:19.330540Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T14:58:58.363Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Adobe Acrobat","vendor":"Adobe","versions":[{"lessThanOrEqual":"26.002.21900","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"26.002.21901","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"Acrobat Reader","vendor":"Adobe","versions":[{"lessThanOrEqual":"26.002.21900","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"26.002.21901","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"Acrobat 2024","vendor":"Adobe","versions":[{"lessThanOrEqual":"24.001.30383","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"24.001.30429","versionType":"custom"}]}],"datePublic":"2026-09-08T17:00:00.000Z","descriptions":[{"lang":"en","value":"Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","availabilityRequirement":"NOT_DEFINED","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","confidentialityRequirement":"NOT_DEFINED","environmentalScore":5.5,"environmentalSeverity":"MEDIUM","exploitCodeMaturity":"NOT_DEFINED","integrityImpact":"NONE","integrityRequirement":"NOT_DEFINED","modifiedAttackComplexity":"LOW","modifiedAttackVector":"LOCAL","modifiedAvailabilityImpact":"NONE","modifiedConfidentialityImpact":"HIGH","modifiedIntegrityImpact":"NONE","modifiedPrivilegesRequired":"NONE","modifiedScope":"UNCHANGED","modifiedUserInteraction":"REQUIRED","privilegesRequired":"NONE","remediationLevel":"NOT_DEFINED","reportConfidence":"NOT_DEFINED","scope":"UNCHANGED","temporalScore":5.5,"temporalSeverity":"MEDIUM","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-416","description":"Use After Free (CWE-416)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:31:14.326Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"tags":["vendor-advisory"],"url":"https://helpx.adobe.com/security/products/acrobat/apsb26-141.html"}],"source":{"discovery":"EXTERNAL"},"title":"Acrobat Reader | Use After Free (CWE-416)","x_generator":{"engine":"cvelib 1.8.0"}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2026-81984","datePublished":"2026-09-08T20:31:14.326Z","dateReserved":"2026-08-27T21:20:45.365Z","dateUpdated":"2026-09-10T14:58:58.363Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 21:18:44","lastModifiedDate":"2026-09-10 15:17:47","problem_types":["CWE-416","CWE-416 Use After Free (CWE-416)"],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-09T16:41:19.330540Z","id":"CVE-2026-81984","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*","versionStartIncluding":"24.001.20604","versionEndExcluding":"24.001.30429","matchCriteriaId":"A6C6B745-7D94-43D9-BD26-1B26EE34DED4"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*","versionStartIncluding":"15.008.20082","versionEndExcluding":"26.002.21901","matchCriteriaId":"B9192F4D-A119-46C4-A167-F500ACB3ACAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*","versionStartIncluding":"15.008.20082","versionEndExcluding":"26.002.21901","matchCriteriaId":"2FEAAE8A-F164-4DCA-8F08-9BC646831744"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"81984","Ordinal":"1","Title":"Acrobat Reader | Use After Free (CWE-416)","CVE":"CVE-2026-81984","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"81984","Ordinal":"1","NoteData":"Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.","Type":"Description","Title":"Acrobat Reader | Use After Free (CWE-416)"}]}}}