CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Active exploitation of Adobe Acrobat Reader zero-day via crafted PDFs since December 2025

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A zero-day vulnerability in Adobe Acrobat Reader has been actively exploited since at least December 2025 using maliciously crafted PDF documents. Threat actors leverage a sophisticated, fingerprinting-style exploit targeting an unpatched flaw, enabling data theft and potential remote code execution or sandbox escape on compromised systems without requiring user interaction beyond opening the PDF. The attacks appear to be selectively targeting users, with phishing lures referencing Russian-language content related to the oil and gas industry.

Timeline

  1. 09.04.2026 12:22 1 articles · 2h ago

    Adobe Acrobat Reader zero-day exploited in the wild since December 2025

    Attackers have exploited an unpatched vulnerability in Adobe Acrobat Reader using crafted PDF documents since at least December 2025. The exploit employs a fingerprinting-style technique to evade detection, targets privileged Acrobat APIs for data theft, and enables potential remote code execution or sandbox escape. Phishing PDFs contain Russian-language lures referencing the oil and gas sector, suggesting a targeted campaign.

    Show sources

Information Snippets