INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Adobe Patches Actively Exploited Zero-Day Flaw

| 2026-04-13 20:52 CRITICAL HIGH
Executive Summary AI-generated
The newly discovered AI-led remediation crisis has exposed a previously unknown vulnerability in Adobe's Acrobat and Reader software, with the high-severity flaw having been exploited for months. The CVE-2026-34621 exploit requires user interaction to trigger the attack, which can lead to remote code execution and sandbox escape exploits. Sophisticated payloads have been dropped on this flaw independently by an independent security researcher, Haifei Li, who uncovered the vulnerability when analyzing a maliciously crafted PDF uploaded to a public threat-sharing platform in March 2026. The initial investigation showed the malware had remained largely unnoticed until November 28, 2025, suggesting ongoing attacks targeting the flaw since then.
Technical Mitigations AI-generated
• The vulnerability allows attackers to execute arbitrary code, potentially leading to remote code execution (RCE) and sandbox escape (SBX) exploits. • Attackers can trigger the flaw by opening a malicious PDF file with no additional clicks or permissions required. • Once triggered, the booby-trapped PDF file silently fingerprints victims' systems before deciding whether they are worth attacking further.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-34621CVE-2026-34621
Target & Sectors
RU
Incident Timeline
‎Nov. 28, 2025
Threat actors exploited an Actively Exploited Zero-Day vulnerability in Adobe Patches that persisted for months.
‎March 23
Threat actors used a zero-day vulnerability in Adobe's software to target the platform on March 23.
organisation VirusTotal
general_metric 64 security tools
‎March 26
Haifei Li discovered the vulnerability by analyzing a maliciously crafted PDF on March 26.
organisation PDF
organisation VirusTotal
general_metric 64 security tools
‎2026/04/06
Threat actors exploited an Actively Exploited Zero-Day vulnerability in Adobe Patches that lingered for months.
‎April 11
Adobe acknowledged the issue on April 11 in an advisory.
‎2026/04/13
Threat actors exploited a zero-day vulnerability in Adobe Acrobat Reader, using PDFs as an attack delivery mechanism.
organisation AI-Led Remediation Crisis Prompts HackerOne
organisation Pause Bug Bounties
infrastructure Windows
infrastructure Macos
organisation Reader for Windows
infrastructure 26.001.21367
infrastructure 26.001.21411
infrastructure 24.001.30356
infrastructure 24.001.30362
infrastructure 24.001.30360
organisation CVSS
organisation CVE-2026
organisation NIST
organisation National Vulnerability Database
organisation NVD
organisation Adobe
organisation Adobe Patches Actively
organisation PDF
organisation EXPMON
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎26.001.21367
Software Version
Metrics
infrastructure
‎26.001.21411
Software Version
Metrics
infrastructure
‎24.001.30356
Software Version
Metrics
infrastructure
‎24.001.30362
Software Version
Metrics
infrastructure
‎24.001.30360
Software Version
Intelligence Sources