CRITICALZero Day
Global

Adobe Reader Zero-Day Exploited for Months: Researcher

·Source: SecurityWeek

Updated:

Executive Summary

Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability. The post Adobe Reader Zero-Day Exploited for Months: Researcher appeared first on SecurityWeek .

Analysis

Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability. The post Adobe Reader Zero-Day Exploited for Months: Researcher appeared first on SecurityWeek .
Source Attribution

Originally published by SecurityWeek on Apr 9, 2026.

Related Threats

CRITICALZero Day

ConnectWise patches critical ScreenConnect authentication failure after five days

ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles”

CVE-2026-84869
CSO Online
CRITICALZero Day

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Auth

CVE-2025-66516CVE-2025-54988
Rapid7
CRITICALZero Day

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team , espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns. Proofpoint, which researched the new attack method along with G

CVE-2026-85046CVE-2026-87491
CSO Online