logo

Adobe Patches Actively Exploited Zero-Day That Lingered for Months

ID: 093ca2ad-b5ce-5011-b89f-06d709da779c

STIX ID: report--093ca2ad-b5ce-5011-b89f-06d709da779c

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Jai Vijayan

...
...

Adobe patched CVE-2026-34621, a high-severity zero-day in Acrobat and Reader exploited in the wild via highly obfuscated PDFs that execute on open to fingerprint victims, steal files and system information, and can stage subsequent remote code execution or sandbox escape payloads; researcher Haifei Li traced samples on VirusTotal (as far back as Nov 28, 2025) and Adobe confirmed exploitation, advising immediate updates and monitoring for the 'Adobe Synchronizer' User-Agent string.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.