logo

Adobe Reader Zero-Day Exploited to Steal Data via Malicious PDFs

ID: 4ec36942-a25c-5af6-8097-a03b8731b16a

STIX ID: report--4ec36942-a25c-5af6-8097-a03b8731b16a

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A zero-day Adobe Reader vulnerability (active since at least Nov 2025) is exploited by specially crafted PDFs (example: "Invoice540.pdf") that run obfuscated JavaScript on open, abuse util.readFileIntoStream and RSS.addFeed to exfiltrate data to 169.40.2.68, and can be used as a staging vector for RCE or sandbox escape; attackers use Russian oil-and-gas themed lures and Adobe has been notified but no patch is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.