Adobe patches critical Acrobat and Reader flaw after exploitation
A security researcher published details last week of a critical flaw in Adobe Acrobat and Reader, where a maliciously crafted PDF could bypass security mechanisms and execute arbitrary code on the host. The vulnerability is tracked as CVE-2026-34621 with a CVSS score of 8.6 and has been exploited in the wild since at least November 2025. On 12 April, Adobe issued a security bulletin with updates for both Acrobat and Reader.
What this means for your organisation
PDF is the format nobody dares block. Invoices, quotes, contracts and applications arrive from outside every day, and they are opened by people with no way of judging whether a file is safe. A flaw exploited for six months before it was fixed also means it is worth looking backwards, not only forwards.
Berigo recommends
- Roll out Adobe's April update to all endpoints, including machines that rarely touch the office network.
- Find older Reader installations on kiosks, meeting room systems and production machines where updates do not happen automatically.
- Review logs from November 2025 onwards for unexpected process launches from PDF readers.
- Consider opening inbound PDFs in a browser-based viewer rather than the installed desktop client.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch