logo

Acrobat Reader zero-day exploited in the wild for many months

ID: b908667e-b49b-58c6-9e5d-4c3eb648c138

STIX ID: report--b908667e-b49b-58c6-9e5d-4c3eb648c138

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-04-09

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

A zero-day Adobe Acrobat Reader vulnerability is being actively exploited via malicious PDF files that execute obfuscated JavaScript to fingerprint victims and fetch additional remote code execution/sandbox escape payloads. Samples submitted to EXPMON and VirusTotal indicate exploitation since at least November 28, 2025; researcher analysis identifies two attacker-controlled IPs (169.40.2.68 and 188.214.34.20), Russian-language decoys suggesting targeting of Russian-speaking infrastructure, and recommended mitigations while Adobe has not yet patched the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.