CVE-2026-34621Active Exploitation(adobe / acrobat)

CRITICALCVSS 8.6 · HIGHCISA KEV

Exploitation observed; activity peaked at 98 mentions and remains active

Immediate actions

  • Patch adobe acrobat systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-1321

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_dc
  • acrobat_reader_dc
  • macos

Threat summary

  • Active exploitation appears in 215 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 310 mentions across 32 observed days

What's happening

  • Active exploitation reported across 215 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 27 signals
  • Patch or workaround mentioned in 214 signals
  • Technical details provided in 152 signals
  • Disclosure: 28 classified signals
  • Peaked 29d ago at 98 mentions (2026-04-13); latest day: 1
  • 310 total mentions across 32 days

Affected systems

Products
acrobatacrobat_dcacrobat_reader_dcmacoswindows

1 version affected across 5 products

Deep dive

Activity timeline310 mentions / 32d
025497498Mentions · 2026-04-11: 21Mentions · 2026-04-12: 70Mentions · 2026-04-13: 98Mentions · 2026-04-14: 31Mentions · 2026-04-15: 22Mentions · 2026-04-16: 6Mentions · 2026-04-17: 10Mentions · 2026-04-18: 6Mentions · 2026-04-19: 4Mentions · 2026-04-20: 3Mentions · 2026-04-21: 3Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-28: 1Mentions · 2026-04-29: 3Mentions · 2026-04-30: 4Mentions · 2026-05-04: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-15: 7Mentions · 2026-05-16: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-28: 1Mentions · 2026-06-01: 1Mentions · 2026-06-07: 1Mentions · 2026-06-10: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-16: 4Mentions · 2026-06-23: 1PoC Mentioned / Linked · 2026-04-11: 3PoC Mentioned / Linked · 2026-04-12: 2PoC Mentioned / Linked · 2026-04-13: 6PoC Mentioned / Linked · 2026-04-14: 2PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-18: 4PoC Mentioned / Linked · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-30: 1PoC Mentioned / Linked · 2026-05-15: 2PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-06-16: 1Exploit Tool / Code · 2026-04-11: 1Exploit Tool / Code · 2026-04-13: 1Exploit Tool / Code · 2026-04-18: 2Exploit Tool / Code · 2026-04-20: 1Exploit Tool / Code · 2026-05-16: 1Exploit Tool / Code · 2026-06-01: 1Active Exploitation · 2026-04-11: 8Active Exploitation · 2026-04-12: 60Active Exploitation · 2026-04-13: 75Active Exploitation · 2026-04-14: 21Active Exploitation · 2026-04-15: 19Active Exploitation · 2026-04-16: 2Active Exploitation · 2026-04-17: 7Active Exploitation · 2026-04-19: 3Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-15: 6Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-16: 2Patch / Workaround · 2026-04-11: 16Patch / Workaround · 2026-04-12: 61Patch / Workaround · 2026-04-13: 75Patch / Workaround · 2026-04-14: 22Patch / Workaround · 2026-04-15: 19Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 6Patch / Workaround · 2026-04-19: 2Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-06-23: 1Technical Details · 2026-04-11: 14Technical Details · 2026-04-12: 31Technical Details · 2026-04-13: 44Technical Details · 2026-04-14: 19Technical Details · 2026-04-15: 12Technical Details · 2026-04-16: 3Technical Details · 2026-04-17: 5Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 2Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-28: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-16: 304-1104-1404-1704-2004-2304-3005-0605-1605-2806-1006-1606-23
Signal classification7 categories
Active Exploitation
14045.2%
Patch
10533.9%
Disclosure
289.0%
General
216.8%
PoC
123.9%
Exploit
31.0%
Referenced assets169 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-1121
Active Exploitation3Disclosure5Exploit1Patch11PoC1
2026-04-1270
Active Exploitation36Disclosure2General1Patch31
2026-04-1398
Active Exploitation46Disclosure6Exploit1False Positive1General2Patch40PoC2
2026-04-1431
Active Exploitation11Disclosure2General5Patch13
2026-04-1522
Active Exploitation15Disclosure2Patch5
2026-04-166
Active Exploitation2Disclosure1General3
2026-04-1710
Active Exploitation4Disclosure1General1Patch3PoC1
2026-04-186
General2PoC4
2026-04-194
Active Exploitation3General1
2026-04-203
Active Exploitation1Disclosure1PoC1
2026-04-213
Active Exploitation2General1
2026-04-221
General1
2026-04-231
General1
2026-04-281
Active Exploitation1
2026-04-293
Active Exploitation1Disclosure1General1
2026-04-304
Active Exploitation1Disclosure1General1PoC1
2026-05-041
Patch1
2026-05-052
Active Exploitation1Disclosure1
2026-05-061
Disclosure1
2026-05-071
Disclosure1
2026-05-157
Active Exploitation6Disclosure1
2026-05-161
PoC1
2026-05-241
Active Exploitation1
2026-05-251
Disclosure1
2026-05-281
Active Exploitation1
2026-06-011
Exploit1
2026-06-071
Active Exploitation1
2026-06-101
Active Exploitation1
2026-06-111
Active Exploitation1
2026-06-121
General1
2026-06-164
Active Exploitation2Disclosure1PoC1
2026-06-231
Patch1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-34621: Adobe Acrobat 2026 Prototype Pollution & JS Injection Chain GitHub: https://github.com/azefzafyoussef/CVE-2026-34621 Write-up: https://youssefazefzaf.com/posts/research-CVE-2026-34621 https://t.co/2KHjYhxCmZ

    Post summary

    A new Adobe Acrobat prototype pollution and JavaScript injection vulnerability (CVE-2026-34621) has been announced with a GitHub-based PoC and detailed write-up available.

    356225816429.5K
    223.7K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🛑 Adobe released emergency fixes for a 9.6 CVSS flaw (CVE-2026-34621) in Acrobat/Reader, confirmed under active exploitation. A prototype pollution bug lets malicious PDFs run arbitrary code via JavaScript. Evidence shows attacks may date back to Dec 2025. 🔗 Read → https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html

    Post summary

    Adobe has released emergency patches for CVE‑2026‑34621, which is currently being actively exploited, as proven by evidence of attacks since December 2025.

    109562827537.3K
    1.7M followersView on X
  • EXPMON@EXPMON_
    Patch

    Adobe has confirmed our findings and has issued an emergency security update for all Adobe Reader (and other affected products) users. https://helpx.adobe.com/security/products/acrobat/apsb26-43.html The underlying exploited zero-day vulnerability has been rated Critical (CVSS 9.6) and is tracked as CVE-2026-34621. It appears that Adobe has determined the bug can lead to arbitrary code execution — not just an information leak. This aligns with our findings and those of other security researchers over the last few days. EXPMON would like to thank Adobe for releasing this emergency security update quickly to help protect users. UPDATE NOW! #expmon #zeroday #0day #pdf #adobereader #CVE-2026-34621

    Post summary

    Adobe released a critical emergency patch for CVE‑2026‑34621 after confirming the zero‑day was actively exploited, with details on severity and impact.

    67631888441.7K
    1.6K followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Patch

    The Adobe Acrobat 0-day has been fixed, and it is tracked as CVE-2026-34621 https://github.com/advisories/GHSA-vcqh-932g-m3qj https://helpx.adobe.com/security/products/acrobat/apsb26-43.html Prototype Pollution 🧐 https://t.co/83ORtZszFt

    Post summary

    Adobe Acrobat CVE-2026-34621, a prototype‑pollution 0‑day, has been fixed; the fix is documented in Adobe’s advisory and a GitHub advisory.

    0110149499.2K
    81.2K followersView on X
  • Gi7w0rm@Gi7w0rm
    Patch

    This 0day is now known as CVE-2026-34621 :) https://helpx.adobe.com/security/products/acrobat/apsb26-43.html

    Post summary

    The tweet announces CVE-2026-34621 and points to Adobe’s security advisory, implying that a patch is available and the vulnerability has been documented by the vendor.

    2202833520.2K
    19.2K followersView on X
  • Joe Security@joe4security
    General

    🚨 CVE-2026-34621 – Adobe Acrobat Reader PDF Vulnerability 📄⚠️ Multiple analysts have taken a deep dive into this threat using 🧪 Joe Reverser — definitely worth exploring: 🔍 Analysis #1 https://buff.ly/T4cobjJ 🔍 Analysis #2 https://buff.ly/BAskKQM Packed with insights into modern PDF exploitation techniques 💡🛠️ #malware #infosec #threatanalysis

    Post summary

    The post references CVE‑2026‑34621 as an Adobe Acrobat Reader PDF vulnerability but does not provide any actionable details, patches, or evidence of exploitation.

    021058223.9K
    7.8K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    CVE-2026-34621: Una vulnerabilidad de tipo «zero-day» en Adobe Acrobat Reader permite la ejecución de código a través de archivos PDF maliciosos https://blog.elhacker.net/2026/05/cve-2026-34621-una-vulnerabilidad-de.html

    Post summary

    The tweet announces a zero‑day flaw in Adobe Acrobat Reader enabling code execution from crafted PDFs, but provides no PoC, exploit, patch, or evidence of active exploitation.

    024053203.8K
    140.9K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-34621 PoC isn't a scanner, it's a campaign weaponizer with 62 pre-authenticated Brazilian fintech targets https://nefariousplan.com/posts/adobe-acrobat-cve-2026-34621-pdf-weaponizer

    Post summary

    The post announces a Proof‑of‑Concept for CVE‑2026‑34621, describing it as a weaponizer targeting 62 Brazilian fintechs, but provides no patch, active exploitation evidence, or technical vulnerability details.

    212158175.7K
    158.1K followersView on X
  • 辻 伸弘 (nobuhiro tsuji)@ntsuji
    Patch

    PDFを開くだけで、このAdobe Readerのゼロデイ脆弱性が悪用される恐れ |Malwarebytes https://www.malwarebytes.com/ja/blog/news/2026/04/simply-opening-a-pdf-could-trigger-this-adobe-reader-zero-day CVE-2026-34621 ・Acrobat DC バージョン 26.001.21367 以前(バージョン 26.001.21411 で修正済み) ・Acrobat Reader DC バージョン 26.001.21367 以前(バージョン 26.001.21411 で修正済み) ・Acrobat 2024 のバージョン 24.001.30356 およびそれ以前(Windows 版は 24.001.30362Windows macOS 版は 24.001.30360 で修正済み)

    Post summary

    The article highlights the zero‑day CVE‑2026‑34621 in Adobe Reader, states it can be triggered by simply opening a PDF, and lists patched versions.

    016144106.9K
    28.6K followersView on X
  • Ryan Naraine@ryanaraine
    Active Exploitation

    "Adobe is aware of CVE-2026-34621 being exploited in the wild." Out-of-band patch 👇🏽 https://helpx.adobe.com/security/products/acrobat/apsb26-43.html

    Post summary

    Adobe confirms CVE‑2026‑34621 is being exploited in the wild and provides an out‑of‑band patch for users.

    09038225.9K
    28.1K followersView on X
  • Haifei Li@HaifeiLi
    General

    Pretty cool, in-depth, root-cause analysis of the bugs used in the Adobe Reader zero-day attack (tracked as CVE-2026-34621 and other CVEs), delivered by the vulnerability research powerhouse @starlabs_sg !

    Post summary

    The statement highlights a root‑cause analysis of Adobe Reader zero‑day vulnerabilities (CVE‑2026‑34621 and others) but provides no concrete technical, PoC, exploit, or patch information.

    111036149.3K
    8.9K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    この内 CVE-2026-34621 の脆弱性について、アドビ社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 Adobe Acrobat および Reader の脆弱性対策について(2026年4月) https://www.ipa.go.jp/security/security-alert/2026/0413-adobereader.html

    Post summary

    Adobe has confirmed active exploitation of CVE‑2026‑34621 and urges users to apply the security patch immediately to mitigate further risk.

    01203273.4K
    14.3K followersView on X
  • Haifei Li@HaifeiLi
    PoC

    There's an article (https://nefariousplan[.]com/posts/adobe-acrobat-cve-2026-34621-pdf-weaponizer/), as well as a script (https://github[.]com/NULL200OK/cve_2026_34621_advanced), claiming a "pop calc" style PoC for the Adobe Reader CVE-2026-34621 0day vulnerability. It looks legitimate, so I just did a quick test. But it didn't go/reproduce like that claimed.. Can someone confirm? Are these stuff AI-generated and I got AI-slopped? like, wtf?

    Post summary

    The post highlights the existence of a PoC for Adobe Reader CVE-2026-34621, provided via an article and a GitHub script, though functional exploitation and patch details are absent.

    23119147.6K
    8.9K followersView on X
  • blackorbird@blackorbird
    Patch

    Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses a critical vulnerability. Successful exploitation could lead to arbitrary code execution. Adobe is aware of CVE-2026-34621 being exploited in the wild. Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Post summary

    Adobe released a security update for Acrobat and Reader addressing CVE-2026-34621, a prototype‑pollution vulnerability that can lead to arbitrary code execution and is actively exploited in the wild.

    1702295.1K
    42.4K followersView on X
  • Haifei Li@HaifeiLi
    Patch

    I was looking at Adobe's regular Patch Tuesday released today https://helpx.adobe.com/security/products/acrobat/apsb26-44.html. Interestingly, Adobe patched two more "Prototype Pollution" bugs, the same bug class like the CVE-2026-34621 which was exploited in the wild & detected by EXPMON. I'm not really in Adobe bug hunting, are "Prototype Pollution" bugs very common in Adobe Reader's JS engine?

    Post summary

    Adobe released patches for several Prototype Pollution bugs, including one that had been exploited in the wild; the post notes the existence of vulnerabilities but does not provide PoC or exploit code.

    17019105.1K
    8.9K followersView on X
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Active Exploitation

    🚨 $ICP ♾️ by @dfinity — THE INTERNET BUILT WITHOUT THE ZERO-DAY CHAOS 🚨 Adobe has confirmed CVE-2026-34621, a critical vulnerability in Adobe Acrobat and Reader (Windows and macOS) that is actively exploited in the wild. Attack characteristics: • Arbitrary code execution • No user interaction required beyond opening a PDF • Exploitation observed since Dec 2025 • Priority-1 emergency patch issued • Users advised to update within 72 hours Affected software: • Acrobat DC • Acrobat Reader DC • Acrobat 2024 This is the recurring Web2 security model problem: Files → local software → scripting engines → OS access. Every layer becomes an attack surface. PDF viewers alone include: • JavaScript engines • Rendering engines • API hooks to operating systems One exploit and attackers gain code execution on the user machine. Why This Keeps Happening Traditional internet architecture relies on: • Local executables • File attachments • Client-side parsing engines • Plugins and scripting runtimes • Continuous patch cycles That architecture guarantees constant zero-day exposure. $ICP ♾️ by @dfinity — A Different Model Internet Computer removes major parts of this attack surface. Architecture: • Applications run as smart contract canisters • Frontend and backend served on-chain • No centralized cloud hosting required • Deterministic execution environment Security primitives: • Chain-key cryptography • Threshold signatures • State replicated across independent nodes • No direct OS access from application logic Result: Attackers cannot compromise the system through local application runtimes and malicious file execution paths. Reality Web2 model = patch → exploit → patch → exploit Internet Computer model = reduce trusted software layers Fewer layers = fewer attack vectors. Every major zero-day proves the same point: The traditional internet stack is fragile. $ICP ♾️ by @dfinity is rebuilding it as a secure world computer. #ICP #DFINITY #CyberSecurity #CloudComputing #Web3 #Blockchain #InternetComputer #Infosec #Security #Crypto #CloudComputing https://www.forbes.com/sites/daveywinder/2026/04/11/pdf-warning-adobe-reader-zero-day-attack-ongoing-since-2025/

    Post summary

    Adobe confirmed that CVE-2026-34621 is actively exploited in the wild, prompting a priority-1 emergency patch and a 72‑hour update window for affected Acrobat products.

    050310711
    1.5K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨 Upozorňujeme na aktivně zneužívanou zranitelnost v Adobe Acrobat Reader a Adobe Acrobat, CVE-2026-34621. Zranitelnost umožňuje vzdálené spuštění libovolného kódu při otevření škodlivě vytvořeného PDF souboru, což může vést k plnému kompromitování postiženého systému. Útok nevyžaduje žádnou interakci nad rámec otevření PDF a týká se systémů Windows i macOS. Ohroženy jsou verze Acrobat DC a Acrobat Reader DC (Continuous) do verze 26.001.21367 a Acrobat 2024 (Classic) do verze 24.001.30356. 📌 Doporučujeme okamžitě aktualizovat na opravené verze: Acrobat DC / Reader DC 26.001.21411, Acrobat 2024 pro Windows 24.001.30362 a pro macOS 24.001.30360.

    Post summary

    CVE‑2026‑34621 is reported to be actively exploited in the wild, enabling remote code execution via malicious PDFs on Windows and macOS for specific Adobe Acrobat versions, and users are urged to update to the patched releases.

    0901841.5K
    4.2K followersView on X
  • ざくろ@オトモはあけび@zacro_magi
    Patch

    しごおわしたけどAdobe通告「Adobe Acrobat(及びReader)の脆弱性」の対応についてICTから通達きたんで 普段あんま使ってないモバイルPCのほうをアプデ中 深刻な脆弱性(CVE-2026-34621) 皆さんも確認してみてくださいまし! 個人PC確認しよ🤔 悪意あるPDF開くだけでPC乗っ取られるのは危険⚠️ https://t.co/IAQlpwlnCq

    Post summary

    The user highlights CVE-2026-34621, notes it as a severe vulnerability, and is applying an update, encouraging others to patch as well.

    130242828
    1.2K followersView on X
  • Davey Winder@happygeek
    Patch

    It's always at the weekend, innit? Adobe urges admins to patch Adobe Acrobat and Reader on Windows and macOS within 72 hours as CVE-2026-34621 attacks confirmed. https://www.forbes.com/sites/daveywinder/2026/04/11/pdf-warning-adobe-reader-zero-day-attack-ongoing-since-2025/

    Post summary

    Adobe reports confirmed attacks against CVE-2026-34621 and urges admins to patch Acrobat and Reader immediately.

    1501682.5K
    14.9K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html

    Post summary

    Adobe announced the release of patches for the actively exploited Acrobat Reader flaw CVE-2026-34621, with evidence of in‑the‑wild attacks ongoing.

    0701441.9K
    157.5K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat_dc---
Appadobeacrobat_reader_dc---
OSapplemacos---
OSmicrosoftwindows---

Explore more