Adobe patches a zero-day in Acrobat DC, Reader DC, and Acrobat 2024, which hackers have been exploiting to remotely plant malware for at least four months
Adobe has patched a vulnerability in its flagship document-reading apps, Acrobat DC, Reader DC and Acrobat 2024, that hackers have been actively exploiting for at least four months.
Context & Ripple Effects
Researchers had already reported that the Reader flaw had been under active exploitation since December 2025, including documents using Russian-language lures; Adobe’s patch turns that warning into an urgent remediation task for users of its document software. The episode also follows Adobe’s earlier emergency response to an actively exploited ColdFusion remote-code-execution flaw, after an initial fix was judged incomplete.
For Adobe, the significance is not just the existence of another zero-day but the length of the known exploitation window: organizations must treat documents handled during that period as potentially hostile, rather than viewing the update as routine maintenance.
First-order effects
- Users of Acrobat DC, Reader DC, and Acrobat 2024 need to deploy the patch promptly, while security teams review exposure to malicious documents delivered during the months-long exploitation period.
- The update removes the disclosed route for remote malware installation in patched versions, but it does not by itself undo compromises that may have occurred before deployment.
Second-order effects
- Organizations may tighten controls around PDF-based inbound documents—such as attachment filtering, sandboxing, and endpoint monitoring—because the reported lures show document readers remain a practical delivery path.
- Adobe’s enterprise customers are likely to scrutinize patch coverage and incident-response records more closely, particularly given the precedent of an Adobe ColdFusion zero-day whose first fix was found incomplete.
Third-order effects
- Repeated exploitation of flaws in widely deployed document and server software reinforces a security model in which patch speed must be paired with detection of already-compromised endpoints.
- If long-lived zero-day campaigns remain common, vendors and customers will face greater pressure to make high-risk applications easier to update and to limit the privileges available to document-processing software.
The trend: This is another instance of attackers exploiting ubiquitous business software before a fix is available, shifting the defensive focus from patching alone to rapid containment and compromise assessment.