#VU125813 Prototype pollution in Adobe Acrobat and Adobe Reader - CVE-2026-34621
Published: April 11, 2026
Adobe Acrobat
Adobe Reader
Adobe
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation when handling PDF files. A remote attacker can trick the victim into opening a specially crafted PDF file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.