Active Zero-Day Exploit Targeting Adobe Reader Users
ID: a368a53f-0015-59d9-b810-6dd19ea79f4d
STIX ID: report--a368a53f-0015-59d9-b810-6dd19ea79f4d
Feed Name: ThreatCluster
### Executive Summary: A high-severity zero-day vulnerability in Adobe Reader is being actively exploited since at least December 2025 to achieve remote code execution via malicious PDF files. The exploit requires only that a user open a PDF, leverages memory corruption and in-memory execution to evade detection, targets Russian-language oil and gas-themed lures, affects the latest Adobe Reader version, and remains unpatched—suggesting involvement of well-resourced (possibly nation-state) actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
