Vulnerabilities · 154 days ago
A new zero-day exploit in Adobe Acrobat Reader breaks the assumption that malicious PDFs act as one-shot attacks. Instead, these PDFs first fingerprint the host environment and exfiltrate system data quietly before delivering tailored remote code execution or sandbox escape payloads. This staged approach means that standard detection methods focusing on visible malware or crashes miss the initial compromise and data leakage.
Security researcher Haifei Li discovered this zero-day, which has been actively exploited since at least December 2025. The exploit works on the latest Adobe Reader version and uses obfuscated JavaScript to collect local system details and send them to attacker-controlled servers. The PDFs contain Russian-language lures tied to oil and gas sector events, indicating targeted campaigns. Although the follow-on payloads have not been fully observed, the capability to fetch and execute additional exploits is confirmed.
This vulnerability shifts the threat model for Adobe Reader users, especially in energy sectors, by enabling attackers to silently gather reconnaissance data before launching full system compromise. The absence of a vendor fix and the exploit's stealthy nature mean that exposure reviews and heightened awareness are critical, as attackers can customize follow-on attacks based on the harvested environment data.
8 sources covering this story
Adobe fixes PDF zero-day security bug that hackers have exploited for months | TechCrunch
It's not clear how many people were compromised by this hacking campaign, but a security researcher said the hackers were targeting victims since at least November 2025.
Adobe Patches Actively Exploited Zero-Day That Lingered for Months
An attacker has been using maliciously crafted PDF files to exploit a zero-day in Adobe Acrobat and Reader for at least four months.
Adobe Patches Reader Zero-Day Exploited for Months
The vulnerability is tracked as CVE-2026-34621 and Adobe has confirmed that it can be exploited for arbitrary code execution.
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
Adobe Reader zero-day exploited since Dec 2025 via malicious PDFs, enabling data theft and potential RCE, prompting urgent security vigilance.
Old Adobe Reader zero-day uses PDFs to size up targets
: Malicious PDFs abuse legit features to harvest system data and decide which victims get a 2nd-stage payload
Acrobat Reader zero-day exploited in the wild for many months - Help Net Security
Unknown attackers have exploited a zero-day Adobe Acrobat Reader vulnerability since November 2025 and possibly even earlier.
Adobe Reader Zero-Day Exploited for Months: Researcher
Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability.
Hackers exploiting Acrobat Reader zero-day flaw since December
Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December.
Adobe Reader zero-day vulnerability in active exploitation
A zero-day vulnerability in Adobe Reader has been exploited since at least December 2025
Part of the PlainSec briefing for 2026-04-14