logo

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

ID: 58761bb6-5840-5500-9515-6b3df57242dc

STIX ID: report--58761bb6-5840-5500-9515-6b3df57242dc

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive Summary:** Researchers observed a previously unknown zero-day in Adobe Reader exploited since at least December 2025 via malicious PDF documents (e.g., "Invoice540.pdf") that execute obfuscated JavaScript to harvest sensitive information, exfiltrate data to 169.40.2.68:45191, and request additional payloads; the exploit is confirmed to work on the latest Adobe Reader and may enable follow-on remote code execution and sandbox escape.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.