216.73.216.233

Adobe Reader 0-day

· Published 13/04/2026 15:14 · Modified 13/04/2026 15:17

Export JSON

Essential information

Published
13/04/2026 15:14
Modified
13/04/2026 15:17
Tags
0-day 2026-04-13 adobe reader
Related entities
4 observables, 1 techniques (mitre), 1 others

Description

On April 7, 2026, a security researcher described an zero-day vulnerability that has been exploited since at least December 2025. The vulnerability allows threat actors to execute privileged Acrobat APIs via specially crafted malicious PDF files that execute obfuscated JavaScript when opened. Exploitation allows attackers to steal sensitive user and system data and to potentially launch additional attacks and remotely execute code. Recommendations: Reduce the risk by automatically scanning PDF email attachments, blocking suspicious files, training users to be wary of unsolicited attachments, and advising users to temporarily avoid using to open PDFs. Reference: https://www.sophos.com/en-us/blog/adobe-reader-zero-day-vulnerability-in-active-exploitation

External references