Adobe today announced an emergency update that will only be released on Thursday, June 16. The upcoming patch will fix a zero-day (where else?) in Flash Player, which is currently being used for targeted attacks.

According to Anton Ivanov and Costin Raiu of Kaspersky, the vulnerability is already being used in targeted attacks.
The vulnerability identifier registered for this zero-day is CVE-2016-4171, and Adobe reports that it affects Flash Player 21.0.0.242 as well as older versions that run on Windows, Macintosh, Linux and Chrome OS.
Flash Player 21.0.0.242 is the company's latest release. Thus this means that the zero-day affects all systems that use Flash.
The vulnerability helps an attacker to crash a Flash Player installation in an unsafe way, which allows them to subsequently run malicious code on the victim's system and take over its management.
If you are using Flash Player, immediately disable the application or the plugin until at least Adobe releases the patch…
