A serious security issue affecting Adobe document-reading applications has been addressed through a recent patch. The vulnerability, identified as CVE-2026-34621, has been under active exploitation for at least four months, with hackers using it to install malware on users' devices via malicious PDF files.
This exploit mainly targets certain versions of Adobe Reader on both Windows and macOS platforms. The specific number of individuals impacted by this hacking campaign remains unknown. Security researcher Haifei Li uncovered the vulnerability when a harmful PDF was uploaded to his malware detection system, revealing its existence as early as late November 2025.
Adobe has confirmed that the bug is classified as a zero-day, meaning it was being exploited before a fix could be issued. As a precaution, the company advises all users of Acrobat DC, Reader DC, and Acrobat 2024 to ensure their software is updated to the newest versions to mitigate any risks associated with this vulnerability.