CVE-2026-34622Disclosure(adobe / acrobat)

MEDIUMCVSS 8.6 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch adobe acrobat systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_dc
  • acrobat_reader_dc
  • macos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-14); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
acrobatacrobat_dcacrobat_reader_dcmacoswindows

1 version affected across 5 products

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-04-14: 5Mentions · 2026-04-19: 1Mentions · 2026-04-22: 1Mentions · 2026-05-06: 1Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-04-14: 5Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-19: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-06: 104-1404-1904-2205-06
Signal classification2 categories
Disclosure
450.0%
Patch
450.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-145
Disclosure2Patch3
2026-04-191
Disclosure1
2026-04-221
Patch1
2026-05-061
Disclosure1
Full discourse8 posts
  • greenapple / M.Asato@greenapple_w
    Patch

    I originally started digging into this because the 0-day mentioned in your blog caught my eye. During my investigation, the patch came out, but I noticed there was still a remaining bug on the JS side and reported it as CVE-2026-34626. I had assumed code execution was no longer on the table, so CVE-2026-34622 is really interesting.

    Post summary

    The author confirms that a patch has been released to fix a lingering JavaScript‑side issue (CVE‑2026‑34626) and notes interest in a separate CVE, but no proof of exploitation or technical details are provided.

    251251413.8K
    969 followersView on X
  • Haifei Li@HaifeiLi
    Patch

    Update. Adobe security team replied to me: “At this time, Adobe does not have any evidence that the vulnerabilities patched in APSB26-44 (CVE-2026-34622 and CVE-2026-34626) have been exploited in the wild.” So it seems to me that these two bugs are more like variants of the CVE-2026-34621 - found by researchers when working on the zero-day exploit, rather than missing bugs in the exploit.

    Post summary

    Adobe confirms that CVE‑2026‑34622 and CVE‑2026‑34626 are patched and shows no evidence of in‑the‑wild exploitation, describing them as variants related to CVE‑2026‑34621.

    0101641.8K
    8.9K followersView on X
  • greenapple / M.Asato@greenapple_w
    Patch

    EXPMONの調査によって発見されたAdobe Acrobat Readerのin-the-wild 0day(CVE-2026-34621)に対して先日パッチが公開されました。しかし、先日のパッチで修正されていなかった別の脆弱性(CVE-2026-34622 / CVE-2026-34626)が明らかになり、先程追加の修正パッチが配布されました! 私が報告した方はコード実行に至らないことを確認してたのですが、もう一方はコード実行にまで到達するとされているためアップデートを推奨します! https://helpx.adobe.com/security/products/acrobat/apsb26-44.html

    Post summary

    Adobe released patches for CVE-2026-34621 and newly discovered CVE-2026-34622/34626, with a recommendation to update due to code‑execution risks and in‑the‑wild exploitation.

    0001152.6K
    969 followersView on X
  • dbugs@ptdbugs
    Disclosure

    📌 Analysis of Prototype Pollution in Adobe Acrobat The article provides a detailed examination of three critical vulnerabilities CVE-2026-34621 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34621), CVE-2026-34622 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34622) and CVE-2026-34626 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and Acrobat 2024, respectively. These issues stem from improper handling of object prototype modifications (prototype pollution) within the JavaScript environment during PDF document parsing. PT ID: PT-2026-32093 Exploitation of these vulnerabilities allows an attacker to inject arbitrary properties into JavaScript runtime objects, potentially leading to sensitive data leakage or arbitrary code execution. For a successful attack, it is sufficient for a user to open a specially crafted PDF file; no additional privileges or user interaction are required. If successfully exploited, the attacker gains the ability to execute code in the context of the Reader process. 📎 Article: https://starlabs.sg/blog/2026/04-three-bugs-walk-into-a-pdf-prototype-pollution-served-cold/ #dbugs_attacks

    Post summary

    The post details three prototype‑pollution CVEs in Adobe Acrobat, explaining how malicious PDFs can lead to code execution without user interaction, but it does not provide PoC code, active exploitation evidence, or patch information.

    01021353
    2.3K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Adobe Acrobat/Reader の脆弱性 CVE-2026-34622/34626 が FIX:任意コード実行の恐れ https://iototsecnews.jp/2026/04/15/adobe-acrobat-reader-vulnerabilities-let-attackers-execute-arbitrary-code/ 今回のアップデートで対処されたのは、プロトタイプ汚染と呼ばれるプログラム上の仕組みに起因する脆弱性です。JavaScript などのスクリプトにより、オブジェクトの標準的な動作が書き換えられてしまうことで、深刻な被害に至ります。 この仕組みが攻撃者に悪用されると、本来は制限されているはずのコード実行やファイル読み取りが許可されてしまう恐れがあります。ご利用のチームは、ご注意ください。 #AcrobatReader #Adobe #CVE202634622 #CVE202634626 #Vulnerability

    Post summary

    The article announces that Adobe has released an update fixing CVE‑2026‑34622 and CVE‑2026‑34626, which involve prototype‑pollution‑based arbitrary code execution in Acrobat/Reader.

    01000184
    486 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34622 Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Pr… https://www.cve.org/CVERecord?id=CVE-2026-34622

    Post summary

    The post references CVE‑2026‑34622, lists affected Acrobat Reader versions, and names the vulnerability type, yet it offers no exploitation details, patches, or evidence of active attacks.

    00000123
    57.2K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) CVE: CVE-2026-34622 PT ID: PT-2026-32704 Vendor: Adobe Product: Acrobat Reader CVSS: 8.6 Credits: n/a Description: Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34622 • https://helpx.adobe.com/security/products/acrobat/apsb26-44.html #dbugs_vuln

    Post summary

    The document announces CVE-2026-34622, detailing its impact, affected Acrobat Reader versions, and CVSS score while referencing a vendor advisory that likely contains patch information. No PoC, exploit code, or active exploitation evidence is provided.

    00000118
    797 followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-34622 | Adobe Acrobat Reader | Vulnerability Description Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier suffer from a Prototype Pollution vulnerability (CWE-1321) that allows arbitrary code execution as the current user. Exploitation occurs when a victim opens a malicious file, enabling attackers to modify object prototype attributes and trigger RCE with user interaction. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Adobe Acrobat Reader Affected Version: >= 0 and <= 24.001.30362 Sources Vendor: https://helpx.adobe.com/security/products/acrobat/apsb26-44.html

    Post summary

    Adobe Acrobat Reader versions up to 24.001.30362 are vulnerable to a prototype pollution flaw that can lead to remote code execution; a vendor patch is available, but exploitation in the wild has not been reported.

    0000082
    8 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat_dc---
Appadobeacrobat_reader_dc---
OSapplemacos---
OSmicrosoftwindows---

Explore more