Skip to content

Adobe fixes critical security flaw exploited through booby-trapped PDFs

Person using a laptop with a red document icon on screen, smartphone, notebook, and glasses on wooden desk.

Adobe has released updates to fix a highly dangerous security vulnerability. Hackers are using it to distribute booby-trapped PDF files.

PDFs are essential. However, before opening a file, you must first make sure you are protected against the malicious PDFs currently circulating, which allow hackers to compromise your computer by exploiting a security flaw. If you use Acrobat DC, Acrobat Reader DC or Acrobat 2024 to open PDFs on Windows or Mac, you may be affected by this issue.

PDFs infected with malware

According to a Malwarebytes report, a researcher called Haifei Li discovered a malicious PDF that exploits a “zero-day” vulnerability in Adobe software, enabling hackers to compromise victims as soon as the file is opened. “When a victim simply opens this PDF file, hidden code within it can read files that Acrobat Reader should not be able to access and send them to an attacker’s server. Some tests show that this allows attackers to download additional malicious code from a remote server and run it on the victim’s computer […]”, the cybersecurity company explains. In other words, merely clicking to open the file can have devastating consequences.

The affected releases are Acrobat DC version 26.001.21367 and earlier, Acrobat Reader DC version 26.001.21367 and earlier, and Acrobat 2024 version 24.001.30356 and earlier. Adobe has acknowledged both the existence of this vulnerability, identified as CVE-2026-34621, and the possibility that malicious actors are already exploiting it. The company also announced updates to resolve the issue on 12 April.

How to protect yourself against these booby-trapped PDFs

To guard against the vulnerability, it is essential to update the affected software to the latest available versions. This is urgent, as these PDFs may already be circulating widely. Evidence suggests that the campaign exploiting this Adobe software vulnerability may have started four months ago.

In its advisory, Adobe also describes the flaw as “critical”. This means that, if exploited, it could run malicious code “potentially without the user’s knowledge”. “To trigger the virus, all that is required is opening a malicious PDF file, nothing more. No additional click or permission is needed”, Malwarebytes also states in its report on the threat.

What we think

The vulnerability is concerning because it could deceive even the most cautious internet users, who may not realise that simply opening a file can infect their PC. Fortunately, Adobe responded quickly and fixed the issue after being notified. However, the effectiveness of the patch will also depend on how widely the update is deployed.

Comments

No comments yet. Be the first to comment!

Leave a Comment