Adobe Reader Zero-Day Patched After Four-Month Wild Exploitation Window
Adobe has patched CVE-2026-34621, an RCE in Acrobat DC, Reader DC, and Acrobat 2024 (Windows and macOS) triggered by opening a malicious PDF. The vulnerability has been confirmed exploited in the wild since at least December 2025 — four months before today's patch. CISA has added it to KEV. No CVSS score is published yet and EPSS remains artificially low (0.061) because the scoring models hadn't ingested exploitation confirmation at the time of calculation. The extended pre-patch exploitation window is the critical factor. Threat actors had months of runway for targeted delivery before any defensive patch existed. Financial services environments carry outsized exposure given PDF ubiquity in client communications, vendor contracts, regulatory filings, and investor materials. The implicit trust PDFs carry in business workflows makes them a persistently favored delivery mechanism for both nation-state operators and financially-motivated actors.
Adobe Reader zero-days have been a preferred delivery vector for APT28, Lazarus Group, and crimeware operators precisely because PDFs don't trigger the suspicion that other file types do. The multi-month patch lag pattern has recurred across prior Acrobat CVEs — Adobe's internal detection posture for in-the-wild exploitation of its own products is a structural weakness at this point, not an isolated miss.