CVE-2026-34621 – Critical Prototype Pollution Zero‑Day in Adobe Acrobat/Reader
Key takeaways
- Critical CVSS 8.6 prototype‑pollution bug enables remote code execution.
- Actively exploited in the wild; attacks observed since Dec 2025.
- Affects Acrobat Reader versions up to 24.001.30356 and 26.001.21367 (and earlier).
- Added to CISA KEV on 2026‑04‑13.
- Immediate patch required; mitigate by disabling JavaScript if patching is delayed.
CVE-2026-34621 is a critical prototype‑pollution vulnerability in Adobe Acrobat/Reader that enables arbitrary code execution when a user opens a crafted PDF.
Overview
The CVE-2026-34621 vulnerability is a prototype‑pollution flaw in the JavaScript engine of Adobe Acrobat and Acrobat Reader. Exploitation allows an attacker who convinces a user to open a crafted PDF to execute arbitrary code with the privileges of the logged‑in user.
Adobe released an emergency patch on 2026‑04‑11 (see the vendor advisory). The vulnerability was subsequently added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026‑04‑13, confirming active exploitation.
For live threat intelligence, signal trends, and a full timeline of activity, see the VulnSocial CVE page.
Technical Details
- Vulnerability type: CWE‑1321 – Prototype Pollution
- Affected components: JavaScript engine used for PDF rendering and scripting.
- Attack vector: Local (requires the victim to open a malicious PDF). CVSS vector
AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. - Impact: Confidentiality, Integrity, and Availability are all rated High because the exploit can run arbitrary native code, potentially installing malware or taking full control of the system.
- User interaction: Required – the victim must open the malicious PDF file.
- Exploitation evidence: Security researchers observed attacks dating back to December 2025; multiple exploit attempts were reported in early April 2026, with a peak of 71 active‑exploitation mentions on 2026‑04‑13.
Severity & Impact
| Metric | Value |
|---|---|
| CVSS Base Score | 8.6 (High) |
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| CWE | CWE‑1321 (Prototype Pollution) |
| CISA KEV | Yes (added 2026‑04‑13) |
The combination of low attack complexity, no privileges required, and high impact makes this a high‑severity issue that must be addressed immediately.
Affected Products
The vulnerability affects Adobe Acrobat and Acrobat Reader on both Windows and macOS. Specific affected releases include:
- Acrobat Reader version 24.001.30356 and earlier
- Acrobat Reader version 26.001.21367 and earlier
- Corresponding classic and continuous‑track releases for Windows and macOS
For the complete list of affected products and version numbers, see the VulnSocial CVE page.
Actionable Insights – What to Do Now
- Deploy the emergency patch immediately. Download the update from Adobe’s advisory (link below) and verify that the installed version is newer than the affected releases.
- Verify patch deployment with an inventory scan (e.g., SCCM, Jamf, or a script that checks the version string of
Acrobat.exe/Acrobat Reader.app). - If patching cannot be completed instantly, mitigate by:
- Disabling JavaScript execution in Acrobat/Reader (
Edit → Preferences → JavaScript → Disable). - Enforcing application whitelisting to block unapproved PDF viewers.
- Using email and web gateways to sandbox or block PDF files from unknown senders.
- Disabling JavaScript execution in Acrobat/Reader (
- Monitor for Indicators of Compromise (IOCs):
- Unexpected launches of
Acrobat.exeorAcrobat Reader.appfrom non‑standard paths. - Child processes spawned by Acrobat (e.g., PowerShell, cmd.exe) shortly after opening a PDF.
- Network traffic to known malicious C2 domains observed after PDF execution.
- Unexpected launches of
- Educate users to treat PDF attachments from unknown sources as suspicious and to avoid opening them without verification.
Remediation & Mitigation Steps
- Download and install the official Adobe update – see the vendor advisory.
- Confirm the version:
Acrobat Reader DCversion >= 24.001.30357 or 26.001.21368. - Disable PDF JavaScript (temporary mitigation):
# In Acrobat/Reader UI: Edit → Preferences → JavaScript → Uncheck "Enable Acrobat JavaScript" - Apply endpoint protection: Ensure EDR/AV solutions are updated to detect malicious PDF payloads.
- Update security policies: Add rule to block execution of Acrobat from unknown locations and enforce least‑privilege execution contexts.
Bottom Line
CVE-2026-34621 is a critical prototype‑pollution zero‑day in Adobe Acrobat/Reader that is actively exploited. With a CVSS score of 8.6, it enables arbitrary code execution when a user opens a malicious PDF. Immediate patching is the only reliable defense; until patches are applied, disable JavaScript in Acrobat and enforce strict PDF handling policies.
References
- Adobe Security Advisory: https://helpx.adobe.com/security/products/acrobat/apsb26-43.html
- CISA KEV entry: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34621
- VulnSocial CVE page (live data): https://vulnsocial.com/cve/CVE-2026-34621
#CVE202634621 #Critical #RCE #Adobe #AcrobatReader #CISAKEV #PrototypePollution #ZeroDay
