PDF Warning—Adobe Reader Zero-Day Attack Ongoing Since 2025

TL;DR AI
2 min readKey summary
Threat actors have exploited an Adobe Reader zero-day since at least December 2025.
The flaw is still unpatched and works in the latest Adobe Reader release.
Opening a PDF is enough to trigger the exploit; no extra user action is needed.
The bug can invoke privileged Acrobat APIs and may target part of Reader's JavaScript engine.
Attack documents use Russian-language lures about Russia's oil and gas industry, and Adobe security bulletin pages do not mention the attacks yet.



