Prototype pollution in Adobe Reader and Adobe Acrobat - CVE-2026-34621
Published: April 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation when handling PDF files. A remote attacker can trick the victim into opening a specially crafted PDF file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Adobe Acrobat
How to mitigate CVE-2026-34621
Adobe Acrobat - addressed in versions 24.001.30360, 24.001.30362, 2026.001.21411