← Vulnerability feed

Vulnerability record · CVE-2026-34621 · published 11 April 2026

CVE-2026-34621: Adobe Acrobat Reader prototype pollution leads to code execution

Adobe · Acrobat Dc

Adobe Acrobat and Reader (versions 24.001.30356, 26.001.21367 and earlier) are affected by prototype pollution (CWE-1321) that can result in arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue that matters to any organization with Acrobat or Reader deployed on endpoints.

8.6 CVSS 3.1 High CISA KEV since 13 Apr 2026 EPSS 2.2% · top 18.4% CWE-1321 · Prototype pollution
8.6CVSS 3.1 base score
2.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
28 Aug 2026Last modified by NVD

Description

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation, allows arbitrary code execution, and has a near-term federal remediation deadline of 2026-04-27.

What it is

Adobe Acrobat and Reader (versions 24.001.30356, 26.001.21367 and earlier) are affected by prototype pollution (CWE-1321) that can result in arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue that matters to any organization with Acrobat or Reader deployed on endpoints.

Impact

An attacker who gets a victim to open a crafted file can execute arbitrary code with the victim's privileges, giving full control of the user's session and data. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached locally via a malicious file opened in Acrobat or Reader; the vector is AV:L/PR:N/UI:R, so no authentication is required but user interaction (opening the file) is mandatory. Delivery is likely through email attachments, downloads or web-hosted PDFs, though the record does not specify the delivery channel.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 with a remediation due date of 2026-04-27, indicating exploitation in the wild; EPSS 30-day probability is 0.07086 (93.9th percentile). No ransomware campaign use is documented.

What to do

  • Update Acrobat and Reader to the fixed versions listed in Adobe security bulletin apsb26-43; patch is the primary action.
  • If patching cannot be completed before the CISA due date, apply the mitigations in the vendor advisory or discontinue use of the affected product per BOD 22-01 guidance.
  • Restrict opening of untrusted PDFs and other files that invoke Acrobat or Reader, and block or sandbox such attachments at the email and web gateways.
  • Enable Acrobat protected view/Enhanced Security and disable JavaScript where operationally feasible to reduce the attack surface.
  • Track patch compliance for Acrobat and Reader across endpoints and prioritize internet-facing or high-value user systems.

Detection

  • Monitor for Acrobat or Reader child processes spawning unusual executables, scripts or command shells after a document is opened.
  • Hunt for suspicious PDF files delivered via email or download that are opened shortly before anomalous process creation on the same host.
  • Review endpoint telemetry for prototype-pollution-related crashes or abnormal memory behavior in Acrobat/Reader processes.
  • Check for known exploitation indicators against the CISA KEV entry and Adobe advisory, and alert on repeated attempts to open untrusted documents.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-34621 to the Known Exploited Vulnerabilities catalog on 13 April 2026 as "Adobe Acrobat and Reader Prototype Pollution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 April 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34621 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2018-4990Adobe Acrobat and Reader double free allows code executionAdobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and e…KEVEPSS 36%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed

Source: NIST National Vulnerability Database (record CVE-2026-34621), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.