Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
VulnerabilitiesCyberDeltaForce Newsroom

CVE-2026-80161: Acrobat Reader Access of Resource Using Incompatible Type ('Type Confusion') vulnerability

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. A security weakness in Acrobat Reader is being tracked as CVE-2026-80161.

NIST NVDSep 10, 2026, 4:18 AM UTC3 min readCVE-2026-80161
IN 30 SECONDS

Understand the story quickly

What happenedSource reporting

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user.

Who or what is affectedSource reporting

The description places that code execution in the context of the current user, so the practical impact depends partly on what that user account can access.

Why it mattersSource reporting

An attacker could exploit this vulnerability to execute arbitrary code.

Defender next stepCDF guidance

Inventory Acrobat Reader deployments and confirm whether the affected component and vulnerable release are present.

THE NEWS

The full story

Source-grounded reporting, presented as a continuous narrative.

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. A security weakness in Acrobat Reader is being tracked as CVE-2026-80161. The description places that code execution in the context of the current user, so the practical impact depends partly on what that user account can access.

An attacker could exploit this vulnerability to execute arbitrary code. In a realistic sequence, an attacker would first need to get that crafted content in front of someone using Acrobat Reader, for example through a message, download, shared file or another normal content-delivery path. When Acrobat Reader processes that content, the bug can be triggered inside the affected application rather than requiring the attacker to log in to the device first.

The disclosed vulnerability affects Acrobat Reader, and organizations should first determine whether that technology exists in their environment. The reported consequence is code execution, meaning successful exploitation could make the affected application or process run attacker-controlled code. Successful exploitation could let an attacker run code on a vulnerable system, which can lead to broader compromise depending on the privileges of the affected service.

SOURCE EVIDENCE

What the reporting is based on

NIST NVD

CVE-2026-80161: Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execu

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code.

Open source
CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

CDF ANALYSIS

What this means

Risk depends on whether Acrobat Reader and the affected component are deployed and reachable, because the reported flaw can lead to remote code execution. Exposure, privilege, business criticality and compensating controls should determine remediation priority.

DEFENDER ACTIONS

What security teams should check now

  • Inventory Acrobat Reader deployments and confirm whether the affected component and vulnerable release are present.
  • Apply the vendor patch or mitigation for CVE-2026-80161 and validate the affected path after remediation.
OPEN QUESTIONS

What is not yet confirmed

  • Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards