Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Security

Critical vulnerability in Adobe Acrobat

21 April 2026·Trung Nguyêñ Dúc, Head of Technology
Critical vulnerability in Adobe Acrobat

The Dutch National Cyber Security Centre (NCSC) warns of a critical vulnerability in Adobe Acrobat DC, Acrobat Reader DC and Acrobat 2024. The flaw, registered as CVE-2026-34621, lets an attacker execute code remotely through a crafted PDF file and is already being exploited. The NCSC's message is clear: install the security update immediately.

Zero-day — a vulnerability that is already being exploited before the vendor has an update available. Once the update exists, every day it is not installed counts.

What is going on

The flaw lies in how the software processes certain PDF files. Whoever opens a crafted document, for example as an e-mail attachment, gives an attacker the ability to run code with the user's privileges. From there, further spread within the network is a realistic scenario. The NCSC rates the flaw as very serious (CVSS score 9.6), reports that public exploit code is available and that small-scale exploitation may have been going on since November last year. The likelihood of large-scale attacks is therefore high.

Why this affects every organisation

Acrobat and Reader are installed on almost every workplace, and PDF is the format for quotes, invoices and contracts. That ubiquity is exactly what makes this flaw so useful to attackers: one convincing attachment to one employee is enough. With this kind of vulnerability, the time between disclosure and abuse is usually measured in days, not weeks.

What you can do now

  • Update immediately to the latest version of Acrobat and Reader, on workplaces and servers alike.
  • Enable automatic updates so future patches arrive by themselves.
  • Use central patch management to verify that every device is really updated, including laptops that rarely visit the office.
  • Warn employees not to open unexpected PDF attachments and to report suspicious e-mail.
  • Make sure EDR protection runs on every device: it stops suspicious behaviour even when an update has not been installed yet.

How Qteco handles this for clients

For our managed clients this is largely invisible. Monitoring flags vulnerable versions, and patch management rolls out the update across the whole device estate within the agreed SLA. Meanwhile EDR watches every device for abnormal behaviour. "Update now" becomes a controlled and verifiable process instead of a manual hunt across all workplaces.

Frequently asked questions

How do I know whether our version is vulnerable?

Open Acrobat or Reader and check "Check for updates" under Help. If an update is waiting, your version is vulnerable. In a managed environment your IT partner sees this centrally for all devices at once.

Is an antivirus scanner enough protection?

No. A classic virus scanner recognises known files, not the abuse of a flaw in legitimate software. EDR protection looks at behaviour and intervenes when Acrobat suddenly starts code that does not belong there. The update remains the real fix.

What if an employee already opened the attachment?

Disconnect the device from the network, change that user's passwords and have the device examined. Report the incident internally and, if personal data is involved, to the Dutch Data Protection Authority within 72 hours.

Not sure whether your environment is up to date? See how managed IT covers patch management and EDR as standard, or get in touch: we are happy to take a look.

Sources

  1. Kwetsbaarheid in Adobe Acrobat DC, Acrobat Reader DC en Acrobat 2024 — NCSC
  2. Beveiligingsadvies NCSC-2026-0111 — NCSC

Read also

Firewalls and VPNs under fire: how to keep the door shut

NCSC warns: critical WordPress flaw actively exploited

Citrix NetScaler exploited before a patch existed

Ready to run worry-free?

Book a no-obligation introduction. We map your IT and security and show where the difference lies.

Book a call →