CVE-2026-82001
Analyzed Analyzed - Analysis Complete

Uncontrolled Resource Consumption in Acrobat Reader

Vulnerability report for CVE-2026-82001, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: Adobe Systems Incorporated

Description

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
adobe acrobat From 24.0.0 (inc) to 24.001.30429 (exc)
adobe acrobat_dc From 15.008.20082 (inc) to 26.002.21901 (exc)
adobe acrobat_reader_dc From 15.008.20082 (inc) to 26.002.21901 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Acrobat Reader is an Uncontrolled Resource Consumption issue that can cause a denial-of-service. An attacker can exploit it by making the application consume excessive system resources, leading to a crash or freeze. The attack requires user interaction, meaning a victim must open a specially crafted malicious file to trigger the issue.

Detection Guidance

This vulnerability requires user interaction to exploit, so detection involves monitoring for unusual resource consumption when opening PDF files. Check system performance metrics like CPU, memory, and disk usage spikes during PDF processing. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could cause Acrobat Reader to become unresponsive or crash, disrupting your ability to view or edit PDF files. It may also slow down your system while the application struggles with resource exhaustion. Since it requires opening a malicious file, users should avoid downloading or opening files from untrusted sources.

Mitigation Strategies

Update Acrobat Reader to the latest version as soon as patches are available. Avoid opening PDF files from untrusted sources. Disable PDF auto-open in email clients and browsers. Monitor Adobe security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82001. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart