Prototype pollution in Adobe Reader and Adobe Acrobat - CVE-2026-34621

 

Prototype pollution in Adobe Reader and Adobe Acrobat - CVE-2026-34621

Published: April 11, 2026


Vulnerability identifier: #VU125813
CSH Severity: Critical
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34621
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation when handling PDF files. A remote attacker can trick the victim into opening a specially crafted PDF file and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild. 


Affected software

Adobe Reader
Adobe Acrobat

How to mitigate CVE-2026-34621

Install updates from vendor's website.

Adobe Reader - update to 26.001.21411
Adobe Acrobat - addressed in versions 24.001.30360, 24.001.30362, 2026.001.21411

External References

Related Security Bulletins