Attackers are actively exploiting an unpatched Adobe Reader/Acrobat zero-day through malicious PDF files that trigger when a victim simply opens the document. Research from EXPMON says the exploit has been used since at least December and works against the latest Reader versions, abusing Acrobat JavaScript and internal APIs including util.readFileIntoStream and RSS.addFeed to bypass sandbox protections, read local files, fingerprint the host, and exfiltrate data to attacker-controlled infrastructure.
The malicious PDFs reportedly contain hidden Base64-encoded objects and can fetch additional encrypted JavaScript payloads when a target matches attacker criteria, creating a path to follow-on attacks such as remote code execution or sandbox escape. Analysts said some lures were written in Russian and themed around developments in the Russian oil and gas sector. Adobe was notified through responsible disclosure, but no patch was available at the time of reporting; defenders were urged to avoid untrusted PDFs and monitor or block traffic to 169.40.2.68:45191 and HTTP/HTTPS requests using the Adobe Synchronizer User-Agent string.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
STAR Labs reported that the in-the-wild Acrobat/Reader exploitation involved a prototype-pollution-based chain spanning CVE-2026-34621, CVE-2026-34622, and CVE-2026-34626. Their reverse engineering indicated Adobe first patched CVE-2026-34621 and then issued a follow-up update two days later for the other two bugs, suggesting the initial emergency fix did not fully break the chain.
Adobe updated its assessment of CVE-2026-34621 on 2026-04-12, lowering the CVSS score from 9.6 to 8.6 after changing the attack vector from network to local. The revision clarified that exploitation requires local access and user interaction, despite the flaw being actively exploited in the wild.
Adobe issued security updates for Acrobat and Acrobat Reader to fix CVE-2026-34621, a prototype pollution vulnerability that was being actively exploited in the wild via malicious PDF files. The patches covered affected Windows and macOS product lines including Acrobat DC, Acrobat Reader DC, and Acrobat 2024.
Threat intelligence analysis found the malicious PDFs used Russian-language lures tied to current events in the Russian oil and gas industry, indicating targeted social engineering in the exploitation campaign.
Public reporting revealed the exploit's use of Acrobat JavaScript, hidden Base64-encoded PDF objects, and abused internal APIs, along with indicators including traffic to 169.40.2.68:45191 and the "Adobe Synchronizer" User-Agent string. Defenders were advised to avoid untrusted PDFs and monitor or block related traffic.
Researchers using the EXPMON threat-hunting system identified the actively exploited, unpatched Adobe Reader zero-day and responsibly disclosed the vulnerability to Adobe Security. At the time of reporting, no patch was available and Adobe had not publicly responded.
On 2026-03-26, researcher Haifei Li identified a suspicious PDF after EXPMON flagged it despite low antivirus detection on VirusTotal. Analysis showed the sample exploited a zero-day against fully updated Adobe Reader and helped uncover the active campaign.
Attackers were exploiting an Adobe Reader zero-day through malicious PDF documents by at least December 2025. The exploit required only that a victim open the PDF and enabled theft of local data, with potential for follow-on remote code execution or sandbox escape.
Security researcher Haifei Li reported that unknown attackers had been exploiting the Adobe Acrobat Reader zero-day via malicious PDF files since at least November 2025. The finding pushes the known start of the campaign earlier than previously documented.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
25 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcetechrepublic.com
Open sourcetechcrunch.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcejusthaifei1.blogspot.com
Open sourcepub.expmon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.