Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December. The attacks have been discovered by security researcher Haifei Li (the founder of the sandbox-based exploit-detection platform EXPMON), who warned on Tuesday that the attackers are using what he described as a "highly sophisticated, fingerprinting-style PDF exploit" to target an undisclosed Adobe Reader security flaw. Li also said that these attacks have been targeting Adobe users for at least 4 months, stealing data from compromised systems using privileged util.readFileIntoStream and RSS.addFeed Acrobat APIs, and deploying additional exploits. "This 'fingerprinting' exploit has been confirmed to leverage a zero-day/unpatched vulnerability that works on the latest version of Adobe Reader without requiring any user interaction beyond opening a PDF file," Li warned. "Even more concerning, this exploit allows the threat actor to not only collect/steal local information but also potentially launch subsequent RCE/SBX attacks, which could lead to full control of the victim's system." Haifei Li has disclosed a long list of security vulnerabilities in Microsoft, Google, and Adobe software, many of which have been exploited in zero-day attacks. Threat intelligence analyst Gi7w0rm, who also analyzed this Adobe Reader exploit, found that PDF documents pushed in these attacks contain Russian-language lures referencing ongoing events in the Russian oil...
Hackers exploiting Acrobat Reader zero-day flaw since December
BleepingComputer
·Sergiu Gatlan
·Published Apr 9, 2026
·Updated
Affected Software
1 affected component
Adobe Reader
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a zero-day vulnerability in Adobe Reader by hackers using malicious PDF documents.
2
What security implications are discussed in the article?
The article highlights the serious security risks associated with the zero-day flaw, which can lead to unauthorized access and exploitation of users' systems.
3
Since when have hackers been exploiting the Acrobat Reader vulnerability?
Hackers have been exploiting the zero-day vulnerability in Acrobat Reader since at least December.
4
Who identified the zero-day exploit in Adobe Reader?
The vulnerability was discovered by security researcher Haifei Li.
5
What products or software are affected by this zero-day flaw?
The affected software is Adobe Reader.