2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Adobe Reader Zero-Day Abused by Malicious PDFs Since December 2025


Security analysts report that threat actors have been leveraging an unpatched zero-day flaw in Adobe Reader via specially crafted PDF files as early as December 2025. The vulnerability was described in research shared by Haifei Li of EXPMON, who characterized the exploit as a sophisticated PDF-based attack chain.

EXPMON’s analysis identified an initial malicious sample named “Invoice540.pdf” that surfaced on the VirusTotal service on November 28, 2025. A related file was later uploaded to VirusTotal on March 23, 2026, indicating the campaign has persisted for several months.

The use of a filename such as “Invoice540.pdf” suggests social-engineering tactics intended to entice recipients into opening the document in Adobe Reader. When viewed, the PDF triggers concealed JavaScript routines that collect sensitive information from the host and can request additional payloads from remote infrastructure.

Independent researcher Gi7w0rm noted in an X post that the observed PDFs include lures written in Russian and reference ongoing issues tied to Russia’s oil and gas sector. According to the researchers, the sample functions as a first-stage exploit with capabilities to harvest and exfiltrate various data types and, potentially, to pave the way for remote code execution (RCE) and sandbox escape (SBX) attacks.

Li explained that the exploit takes advantage of an unknown, unpatched weakness in Adobe Reader that enables the malicious file to call privileged Acrobat APIs. Testing confirmed the attack works against the most recent release of Adobe Reader available at the time of analysis.

The malicious documents are configured to send stolen information to a command-and-control endpoint at “169.40.2[.]68:45191” and to download additional JavaScript to be executed locally. This two-way interaction allows the attackers not only to siphon data but also to deploy further code tailored to the compromised environment.

Researchers warn that this delivery mechanism could facilitate broad data collection, advanced host fingerprinting, and preparation for subsequent operations such as delivering exploits that achieve code execution or escape sandbox constraints. However, the specific nature of any follow-up exploit remains unclear because the analysis team did not receive a response from the remote server.

The lack of a reply may indicate that the server enforces environment checks and only responds to connections originating from targets that meet certain criteria, or that the infrastructure observed was part of a staging environment used by the attackers.

Despite those unknowns, Li emphasized that the combination of an unpatched zero-day capable of widespread information theft and the realistic potential for later RCE/SBX exploitation is a serious concern for defenders and warrants heightened vigilance across the security community.

Adobe has released security updates for the vulnerability (CVE-2026-34621, CVSS score: 9.6).

First published on April 11, 2026.
Last updated on April 24, 2026.