惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
B
Blog RSS Feed
D
DataBreaches.Net
L
LangChain Blog
月光博客
月光博客
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
V
Visual Studio Blog
美团技术团队
Jina AI
Jina AI
博客园 - 司徒正美
雷峰网
雷峰网
Last Week in AI
Last Week in AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
小众软件
小众软件
罗磊的独立博客
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta

Forbes - Innovation

2 Personality Traits That Make Self-Control Easier, By A Psychologist Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2
Adobe Attacks Underway—Windows And Mac Users Given 72 Hou...
Davey Winder · 2026-04-11 · via Forbes - Innovation
Adobe Acrobat Reader (PDF) logo on smartphone screen.

Adobe Reader zero-day attacks ongoing.

SOPA Images/LightRocket via Getty Images

Update April 11: Adobe has now confirmed that CVE-2026-34621, a critical vulnerability affecting users of Adobe Acrobat and Reader on both Windows and macOS platforms, is already being exploited by attackers. The exploit can lead to arbitrary code execution and requires no user interaction beyond opening a malicious PDF document. Adobe has advised that the security update should be installed within 72 hours.

The use of Adobe PDF documents in cybersecurity threats is far from uncommon; they represent a primary “malicious document” attack surface for those using social engineering tactics, for example. When it comes to zero-day exploits targeting the Adobe Reader used to view such files, however, that’s a different matter. So, when a security researcher reveals a “highly sophisticated, fingerprinting-style PDF exploit" being used against such a zero-day vulnerability, you need to take it seriously. Perhaps even more so when those attacks have been ongoing since December 2025.

ForbesNew Google Security Warning For Android 14, 15 And 16 Users—Update Now

Sophisticated Adobe PDF Zero-Day Exploit—Attacks Against Adobe Reader Ongoing

A security researcher has confirmed that threat actors have been exploiting a zero-day vulnerability that exists within Adobe Reader, used to view Adobe PDF files, since at least December 2025. The critical vulnerability has now been comfirmed as CVE-2026-34621 by Adobe.

Haifei Li, best known for developing a sandbox-based exploit-detection platform called EXPMON, has warned that attackers are exploiting a “zero-day/unpatched vulnerability in Adobe Reader that allows it to execute privileged Acrobat Application Programming Interfaces, and it is confirmed to work on the latest version of Adobe Reader.”

The use of maliciously crafted Adobe PDF documents is, as mentioned previously, not exactly shocking nor new. Just ask Dropbox, Microsoft or PayPal users, and they will unhappily confirm that. This zero-day attack, however, isn’t reliant on a victim clicking a dodgy link in the PDF attachment, though. It’s much worse than that. The exploit “works on the latest version of Adobe Reader without requiring any user interaction beyond opening a PDF file,” Li warned.

ForbesAngry Hacker Drops Microsoft Zero-Day Exploit, 1 Billion Users WarnedBy Davey Winder

Another security researcher, posting on X as Gi7w0rm, said that it “seems to exploit part of Adobe Reader’s JavaScript engine,” and that the documents that have been seen to be used in attacks so far “contain Russian language lures and refer to issues regarding current events related to the oil and gas industry in Russia.”

I reached out to Adobe for a statement and advice for users, and a spokesperson confirmed that a security bulletin has now been added to address the vulnerability and that an update is now available for Adobe Acrobat and Reader for Windows and macOS.

Adobe security bulletin for CVE-2026-34621.

Adobe

The following products have updates available, and all have been given a priority one status by Adobe:

  • Acrobat DC
  • Acrobat Reader DC
  • Acrobat 2024

Users can update their software manually by choosing the Help|Check for Updates menu option. Adobe said that the software will “update automatically, without requiring user intervention, when updates are detected. “

As far as administrators in managed environments are concerned, Adobe recommended installing the updates “via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM for Windows, or on macOS, Apple Remote Desktop and SSH." Sorry to spoil your weekend folks.