Adobe近日发布了针对Acrobat和Reader零日漏洞的修复补丁,而此前攻击者已利用该漏洞活跃了数月之久。
Adobe于4月11日发布补丁,修复了Acrobat和Reader中的零日漏洞CVE-2026-34621。该漏洞影响Windows和macOS平台,可导致任意代码执行。攻击者利用恶意PDF中高度混淆的JavaScript,通过合法API收集系统信息,并可下载二阶段载荷实现远程控制或沙箱逃逸。研究人员发现,此攻击活动最早可追溯至2025年底,部分诱饵文件以俄语书写并涉及油气行业主题,疑为定向攻击。
Adobe has released an emergency security update for Acrobat Reader to fix a vulnerability, tracked as CVE-2026-34621, that ...
Adobe has released a fix for an Acrobat and Reader zero-day that attackers had been exploiting for months. The patch, shipped on April 11, addresses CVE-2026-34621, a critical vulnerability in Acrobat ...
黑客已悄然利用Adobe Acrobat Reader中疑似存在的一个零日漏洞长达数月之久,通过植入恶意代码的PDF文件对目标进行情报侦察,从而决定哪些对象值得发动全面攻击。 沙箱漏洞检测系统EXPMON的创始人、安全研究员李海飞表示,此次攻击活动使用的恶意PDF文件在打开的瞬间即可触发执行,即便是已完全更新的Reader版本同样无法幸免,用户除了查看文件外无需进行任何其他操作。 该漏洞利用经过高 ...
Researcher Haifei Li, founder of the exploit detection platform EXPMON, discovered a sophisticated attack that uses PDF files to spy on and potentially ...
Adobe公司近日针对旗下两款热门软件Acrobat和Acrobat Reader发布了紧急安全更新,以应对一个被标记为CVE-2026-34621的零日漏洞。该漏洞被归类为原型链污染(Prototype Pollution,CWE-1321),其严重性极高,CVSS评分高达8.6分,攻击者可能利用此漏洞在受影响设备上执行任意代码。
The vulnerability, assigned the CVE identifier CVE-2026-34621, carries a CVSS score of 9.6 out of 10.0. Successful ...
Adobe patches CVE-2026-34621 after active exploitation since Dec 2025, preventing remote code execution via malicious PDFs.
A credit card skimmer campaign discovered in early 2025 and still actively tracked as of April 2026 has compromised an ...
Adobe Acrobat and Reader users are under attack from hackers using a zero-day vulnerability. Update within 72 hours, Adobe ...