ZeroHour

CVE-2026-34621

KEVmass

Actively Exploited Prototype Pollution RCE in Adobe Acrobat and Reader

CISA: Adobe Acrobat and Reader Prototype Pollution Vulnerability

CVSS 3.1
8.6 high
EPSS
7%p94
Published
()
KEV added
AI analysis

Adobe Acrobat and Acrobat Reader are affected by a prototype pollution vulnerability (CWE-1321) in which improperly controlled modification of object prototype attributes can lead to arbitrary code execution in the context of the current user. Attackers trigger the flaw by convincing a victim to open a malicious file, typically a crafted PDF, so user interaction is required. Successful exploitation yields code execution as the victim, with the CVSS scope-changed metric indicating impact that extends beyond the vulnerable component. Anyone running Acrobat or Reader versions 24.001.30356 or earlier or 26.001.21367 or earlier is affected. The flaw is being actively exploited in the wild — reportedly via malicious PDFs since December 2025 as a zero-day — and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 after fixes shipped in Adobe's April 2026 Patch Tuesday release; EPSS assigns a 7.1% probability of exploitation within 30 days (94th percentile).

What to do: Upgrade Acrobat and Reader to a version later than 24.001.30356 (24.001 series) or 26.001.21367 (26.001 series) via Adobe's April 2026 security update, and audit installed versions across all endpoints. As a CISA KEV entry, US federal agencies must apply the vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. Until patched, treat PDFs from untrusted sources with caution and monitor for suspicious child-process activity spawned by Acrobat/Reader when files are opened.

Affected
Adobe Acrobat Reader (Acrobat Reader DC)24.001.30356 and earlier; 26.001.21367 and earlier
Adobe Acrobat (Acrobat DC)24.001.30356 and earlier; 26.001.21367 and earlier
Estimated exposure
masshundreds of millions of Acrobat/Reader installations worldwide, with likely millions still unpatched — Adobe Acrobat/Reader is the world's dominant desktop PDF viewer with an install base in the hundreds of millions, and the affected ranges span Adobe's current release tracks, so the population of affected endpoints plausibly remains in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
acrobat dc, acrobat reader dc, acrobat
Weakness
CWE-1321
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news