CVE-2026-34626Patch(adobe / acrobat)

MEDIUMCVSS 6.3 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch adobe acrobat systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_dc
  • acrobat_reader_dc
  • macos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
acrobatacrobat_dcacrobat_reader_dcmacoswindows

1 version affected across 5 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-19: 1Mentions · 2026-05-06: 1Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-04-14: 3Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 1Technical Details · 2026-05-06: 104-1404-1905-06
Signal classification3 categories
Patch
360.0%
General
120.0%
Disclosure
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-143
Patch3
2026-04-191
General1
2026-05-061
Disclosure1
Full discourse5 posts
  • greenapple / M.Asato@greenapple_w
    Patch

    I originally started digging into this because the 0-day mentioned in your blog caught my eye. During my investigation, the patch came out, but I noticed there was still a remaining bug on the JS side and reported it as CVE-2026-34626. I had assumed code execution was no longer on the table, so CVE-2026-34622 is really interesting.

    Post summary

    The author notes that a patch for a CVE has been released, highlights a remaining JavaScript bug reported as CVE‑2026‑34626, and expresses interest in another CVE, but does not provide technical details or exploitation evidence.

    251251413.8K
    969 followersView on X
  • Haifei Li@HaifeiLi
    Patch

    Update. Adobe security team replied to me: “At this time, Adobe does not have any evidence that the vulnerabilities patched in APSB26-44 (CVE-2026-34622 and CVE-2026-34626) have been exploited in the wild.” So it seems to me that these two bugs are more like variants of the CVE-2026-34621 - found by researchers when working on the zero-day exploit, rather than missing bugs in the exploit.

    Post summary

    Adobe confirms no evidence of in‑the‑wild exploitation for CVE‑2026‑34622 and CVE‑2026‑34626, stating they are variants of CVE‑2026‑34621, and references the patch applied in APSB26‑44.

    0101641.8K
    8.9K followersView on X
  • greenapple / M.Asato@greenapple_w
    Patch

    EXPMONの調査によって発見されたAdobe Acrobat Readerのin-the-wild 0day(CVE-2026-34621)に対して先日パッチが公開されました。しかし、先日のパッチで修正されていなかった別の脆弱性(CVE-2026-34622 / CVE-2026-34626)が明らかになり、先程追加の修正パッチが配布されました! 私が報告した方はコード実行に至らないことを確認してたのですが、もう一方はコード実行にまで到達するとされているためアップデートを推奨します! https://helpx.adobe.com/security/products/acrobat/apsb26-44.html

    Post summary

    Adobe released a patch for the in‑the‑wild CVE‑2026‑34621, but new vulnerabilities (CVE‑2026‑34622/34626) that allow code execution were identified, prompting an update recommendation.

    0001152.6K
    969 followersView on X
  • dbugs@ptdbugs
    Disclosure

    📌 Analysis of Prototype Pollution in Adobe Acrobat The article provides a detailed examination of three critical vulnerabilities CVE-2026-34621 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34621), CVE-2026-34622 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34622) and CVE-2026-34626 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and Acrobat 2024, respectively. These issues stem from improper handling of object prototype modifications (prototype pollution) within the JavaScript environment during PDF document parsing. PT ID: PT-2026-32093 Exploitation of these vulnerabilities allows an attacker to inject arbitrary properties into JavaScript runtime objects, potentially leading to sensitive data leakage or arbitrary code execution. For a successful attack, it is sufficient for a user to open a specially crafted PDF file; no additional privileges or user interaction are required. If successfully exploited, the attacker gains the ability to execute code in the context of the Reader process. 📎 Article: https://starlabs.sg/blog/2026/04-three-bugs-walk-into-a-pdf-prototype-pollution-served-cold/ #dbugs_attacks

    Post summary

    The article discloses three prototype‑pollution CVEs in Adobe Acrobat that could lead to code execution by opening malicious PDFs, but it does not provide PoC, exploit code, or evidence of active exploitation.

    01021353
    2.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34626 Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Pr… https://www.cve.org/CVERecord?id=CVE-2026-34626

    Post summary

    The text lists CVE-2026-34626, affected Adobe Acrobat Reader versions, and identifies the vulnerability type, but provides no PoC, exploit code, active exploitation, or patch details.

    00000115
    57.2K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat_dc---
Appadobeacrobat_reader_dc---
OSapplemacos---
OSmicrosoftwindows---

Explore more