Adobe patches Acrobat/Reader zero-day exploited through PDFs

1 min read
Source: BleepingComputer
Adobe patches Acrobat/Reader zero-day exploited through PDFs
Photo: BleepingComputer
TL;DR

Adobe has issued an emergency security update for Acrobat and Reader to fix CVE-2026-34621, a zero-day that allowed malicious PDFs to bypass sandboxing and run privileged JavaScript, enabling arbitrary file reading and data exfiltration; the flaw was observed in the wild, linked to Russian-language oil-and-gas documents, with affected products including Acrobat DC, Acrobat Reader DC, and Acrobat 2024; Adobe downgraded the severity from 9.6 to 8.6 after changing the attack vector to local, and users should update via Help > Check for Updates or the official installer; exercise caution with PDFs from unknown sources and consider sandboxing suspicious files.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer