logo

Malicious PDF reveals active Adobe Reader zero-day in the wild

ID: 76b5c168-e2af-5838-8768-aae48fe7e0a8

STIX ID: report--76b5c168-e2af-5838-8768-aae48fe7e0a8

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A malicious PDF exploiting an unpatched Adobe Reader zero-day has been observed in the wild; it abuses privileged Acrobat APIs to read arbitrary local files and exfiltrate data, and may lead to remote code execution or sandbox escape. Researchers report Russian-language lures, ongoing campaign activity over months, and at least one observed indicator (188.214.34.20:34123).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.