# Adobe Reader zero-day CVE-2021-28550 exploited

Published: 2021-05-11 · Severity: high
Canonical: https://vorant.io/reports/9be66382-a69c-5e3b-87da-6a3409cf7650/adobe-reader-zero-day-cve-2021-28550-exploited

> Adobe confirmed active exploitation of a vulnerability in Acrobat and Reader, prompting IPA to urge immediate patching.

Japan's IPA issued an alert regarding a vulnerability in Adobe Acrobat and Reader tracked as CVE-2021-28550, disclosed by Adobe in security bulletin APSB21-29. Adobe has confirmed that this vulnerability has been exploited in the wild, elevating the urgency for users to apply patches immediately.

The affected versions span multiple release tracks for both Windows and macOS, including 2021.001.20150 and earlier, 2020.001.30020 and earlier, and 2017.011.30194 and earlier. IPA advises all users of these products to update to the latest version provided by Adobe as soon as possible to mitigate the risk of exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2021-28550 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210512-adobereader.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9be66382-a69c-5e3b-87da-6a3409cf7650/adobe-reader-zero-day-cve-2021-28550-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
