Adobe Acrobat/Reader zero-day exploited in wild
Adobe patched multiple Acrobat and Reader vulnerabilities, including CVE-2026-34621, which Adobe confirms is already being exploited in attacks.
IPA (Japan's Information-technology Promotion Agency) issued an alert on April 13, 2026 regarding a security update released by Adobe on April 11, 2026 for Acrobat and Reader on Windows and macOS. The update addresses multiple vulnerabilities that could cause application crashes or allow an attacker to take control of an affected PC.
One of the flaws, CVE-2026-34621, has been confirmed by Adobe as actively exploited in the wild. IPA warns that damage from this vulnerability could expand and urges users and administrators to apply the update immediately. Affected versions include Acrobat/Reader 26.001.21367 and earlier, and 24.001.30356 and earlier, on both Windows and macOS.
Organizations managing software updates centrally are advised to consult Adobe's security bulletin and prioritize deployment given the confirmed exploitation. No specific threat actor, malware, or campaign has been identified in this advisory.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2026/0413-adobereader.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free