logo

Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw

ID: e21dfcce-5915-50bb-9e27-264a321e6111

STIX ID: report--e21dfcce-5915-50bb-9e27-264a321e6111

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Adobe released emergency updates for CVE-2026-34621, a zero-day in Acrobat/Reader exploited in the wild by malicious PDFs that bypass sandbox restrictions and invoke privileged JavaScript APIs (e.g., util.readFileIntoStream, RSS.addFeed) to read and exfiltrate local files without further user interaction; attacks were observed since at least December and Adobe has published fixes for affected Windows and macOS versions—apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.