Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-34621 | Actively Exploited Prototype Pollution RCE in Adobe Acrobat and Reader Adobe Acrobat and Acrobat Reader are affected by a prototype pollution vulnerability (CWE-1321) in which improperly controlled modification of object prototype attributes can lead to arbitrary code execution in the context of the current user. Attackers trigger the flaw by convincing a victim to open a malicious file, typically a crafted PDF, so user interaction is required. Successful exploitation yields code execution as the victim, with the CVSS scope-changed metric indicating impact that extends beyond the vulnerable component. Anyone running Acrobat or Reader versions 24.001.30356 or earlier or 26.001.21367 or earlier is affected. The flaw is being actively exploited in the wild — reportedly via malicious PDFs since December 2025 as a zero-day — and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 after fixes shipped in Adobe's April 2026 Patch Tuesday release; EPSS assigns a 7.1% probability of exploitation within 30 days (94th percentile). Do: Upgrade Acrobat and Reader to a version later than 24.001.30356 (24.001 series) or 26.001.21367 (26.001 series) via Adobe's April 2026 security update, and audit installed versions across all endpoints. As a CISA KEV entry, US federal agencies must apply the vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. Until patched, treat PDFs from untrusted sources with caution and monitor for suspicious child-process activity spawned by Acrobat/Reader when files are opened. | 8.6 | 7% | KEV |
| masshundreds of millions of Acrobat/Reader installations worldwide, with likely millions still unpatched |
Full article354 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 12, 2026Vulnerability / Endpoint Security
Adobe has released emergency updates to fix a critical security flaw in Acrobat Reader that has come under active exploitation in the wild.
The vulnerability, assigned the CVE identifier CVE-2026-34621, carries a CVSS score of 8.6 out of 10.0. Successful exploitation of the flaw could allow an attacker to run malicious code on affected installations.
It has been described as a case of prototype pollution that could result in arbitrary code execution. Prototype pollution refers to a JavaScript security vulnerability that permits an attacker to manipulate an application's objects and properties.
The issue impacts the following products and versions for both Windows and macOS -
- Acrobat DC versions 26.001.21367 and earlier (Fixed in 26.001.21411)
- Acrobat Reader DC versions 26.001.21367 and earlier (Fixed in 26.001.21411)
- Acrobat 2024 versions 24.001.30356 and earlier (Fixed in 24.001.30362 for Windows and 24.001.30360 for macOS)
Adobe acknowledged that it's "aware of CVE-2026-34621 being exploited in the wild."
The development comes days after security researcher and EXPMON founder Haifei Li disclosed details of zero-day exploitation of the flaw to run malicious JavaScript code when opening specially crafted PDF documents through Adobe Reader. There is evidence suggesting that the vulnerability may have been under exploitation since December 2025.
"It appears that Adobe has determined the bug can lead to arbitrary code execution — not just an information leak," EXPMON said in a post on X. "This aligns with our findings and those of other security researchers over the last few days."
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on April 13, 2026, added CVE-2026-34621 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by April 27, 2026.
(The story was updated after publication to reflect the change in CVSS score from 9.6 to 8.6. In a revision to its advisory on April 12, 2026, Adobe said it adjusted the attack vector from Network (AV:N) to Local (AV:L).)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html