Skip to content
Advertisement
When Appliance Fail?

Adobe fixes PDF zero-day security bug that hackers have exploited for months

It's not clear how many people were compromised by this hacking campaign, but a security researcher said the hackers were targeting victims since at least November 2025.

schedule 14:35 visibility 122 views
Adobe fixes PDF zero-day security bug that hackers have exploited for months
TechCrunch Source: TechCrunch

Adobe has patched a vulnerability in its flagship document-reading apps, Acrobat DC, Reader DC and Acrobat 2024, that hackers have been actively exploiting for at least four months.

The vulnerability, officially tracked as CVE-2026-34621, allows hackers to remotely plant malware on a person’s device by tricking them into opening a maliciously crafted PDF file on their Windows device or macOS computer. The exploit targets a vulnerability in some versions of the Adobe Reader software.

It is not yet known how many people have been affected by this hacking campaign. In a note on its website, Adobe said it was aware that the bug is being exploited in the wild, known as a zero-day, indicating that hackers have been using it to break into people’s computers before Adobe could fix it. 

While it’s not clear who is behind the hacking campaign, the ubiquity of Adobe’s PDF-reading software makes it a consistent target for cyber criminals and government-backed hackers, who have long abused weaknesses in the software to steal data from people’s computers.

Security researcher Haifei Li, who runs the exploit-detection system EXPMON, discovered the vulnerability after someone uploaded a copy of a malicious PDF containing the exploit to his malware scanner. In a blog post, Li wrote that another copy of the malware-ridden PDF first appeared on VirusTotal, another online malware scanner, in late November 2025.

It’s not clear who the hacking campaign was targeting or for what reason, and Li said it was not possible to obtain any additional exploits from the hacker’s servers. But according to Li’s analysis, opening a malicious PDF and triggering the exploit “could lead to full control of the victim’s system” and give the hacker the ability to steal a wide range of data.

Adobe said Acrobat DC, Reader DC, and Acrobat 2024 are affected, and urged users to update their software to the latest versions.

TechCrunch

Originally published at

TechCrunch

open_in_new Read Full Article

Related Articles

Read More

OpenAI’s rogue AI tried to hack another company in May
Science

OpenAI’s rogue AI tried to hack another company in May

In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a serious disruption for the host. Now independent researchers have said that a swarm of OpenAI agents were responsible for the attack. Not only that, but the AI...

The Verge
LG responds to TV spying allegations
Science

LG responds to TV spying allegations

Earlier this week, Gamers Nexus, Level1Techs, and independent security researchers detailed some alarming findings about how LG's TVs are logging and uploading data on its users. Now the company is pushing back against those allegations, saying that...

The Verge
Senegal: Building a home-grown space industry
Science

Senegal: Building a home-grown space industry

Africa’s space ambitions are gathering pace, and Senegal is determined not just to put satellites into orbit, but to build them at home. Senegalese engineers are already mastering satellite manufacturing in France, with the goal of bringing that...

France 24
Your Appliance Broke?
Reliable Repair for