CVE-2026-34621
published 2026-04-11CVE-2026-34621: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype…
PriorityP183high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-04-27
Exploited in the wild
EPSS
7.09%
93.5th percentile
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 24.0.0 < 24.001.30362 | 24.001.30362 |
| adobe | acrobat | >= 24.0.0 < 24.001.30360 | 24.001.30360 |
| adobe | acrobat_dc | < 26.001.21411 | 26.001.21411 |
| adobe | acrobat_reader | <= 26.001.21367 | — |
| adobe | acrobat_reader_dc | < 26.001.21411 | 26.001.21411 |
Detection & IOCsextracted from sources · hover to see the quote
- →Flag PDF files invoking privileged JavaScript APIs util.readFileIntoStream() and RSS.addFeed() — these are the specific APIs abused by the in-the-wild exploit to read local files and exfiltrate data. ↗
- →Hunt for the known malicious PDF sample filename 'yummy_adobe_exploit_uwu.pdf' in email gateways, endpoint telemetry, and sandbox submissions; it was submitted to VirusTotal on or around March 23, 2026 with only 5/64 detections at the time. ↗
- →Threat actors used Russian-language PDF lure documents themed around the oil and gas industry; filter for such documents in email and web proxy logs as a targeting indicator. ↗
- →The exploit bypasses Adobe Reader sandbox restrictions to invoke privileged JavaScript APIs — monitor for Adobe Reader child processes or API calls that escape the sandbox boundary. ↗
- →No user interaction beyond opening the malicious PDF is required; any Adobe Reader process spawning network or file-read activity immediately upon document open should be treated as suspicious. ↗
- →Active exploitation has been observed since at least December 2025 / November 2025; retrospectively hunt endpoint and network logs from that period for indicators of compromise. ↗
- ·Adobe revised the CVSS score and attack vector after initial publication — the attack vector was changed from Network (AV:N) to Local (AV:L), lowering the score from 9.6 to 8.6. Detection rules or risk scoring based on the original network vector should be updated accordingly. ↗
- ·Affected versions span both Windows and macOS; ensure detection and patching coverage applies to both platforms. Fixed versions differ by OS for Acrobat 2024 (Windows: 24.001.30362, macOS: 24.001.30360). ↗
- ·No workarounds or mitigations exist; patching is the only recommended remediation action. CISA remediation due date is 2026-04-27. ↗
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
vulncheck9.6CRITICAL
cisa8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Acrobat and Reader Prototype Pollution Vulnerability
cisa·2026-04-13·CVSS 8.6
CVE-2026-34621 [HIGH] CWE-1321 Adobe Acrobat and Reader Prototype Pollution Vulnerability
Vulnerability: Adobe Acrobat and Reader Prototype Pollution Vulnerability
Affected: Adobe Acrobat and Reader
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://helpx.adobe.com/security/products/acrobat/apsb26-43.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-34621
Remediation Due Date: 2026-04-27
GHSA
GHSA-vcqh-932g-m3qj: Acrobat Reader versions 24
ghsa_unreviewed·2026-04-11
CVE-2026-34621 [CRITICAL] CWE-1321 GHSA-vcqh-932g-m3qj: Acrobat Reader versions 24
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe Acrobat Reader up to 24.001.30356/26.001.21367 File prototype pollution (apsb26-43)
vuldb·2026-04-11·CVSS 9.6
CVE-2026-34621 [CRITICAL] Adobe Acrobat Reader up to 24.001.30356/26.001.21367 File prototype pollution (apsb26-43)
A vulnerability has been found in Adobe Acrobat Reader up to 24.001.30356/26.001.21367 and classified as critical. Affected by this vulnerability is an unknown functionality of the component File Handler. Performing a manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability is identified as CVE-2026-34621. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
VulnCheck
Adobe Acrobat and Reader Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
vulncheck·2026·CVSS 9.6
CVE-2026-34621 [CRITICAL] Adobe Acrobat and Reader Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Adobe Acrobat and Reader Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected: Adobe Acrobat and Reader
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html;
No detection rules found.
No public exploits indexed.
Hackernews
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
blogs_hackernews·2026-04-15·CVSS 9.9
[CRITICAL] April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases.
Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse ( CVE-2026-27681 , CVSS score: 9.9) that could result in the execution of arbitrary database commands.
"The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an a
Krebs
Patch Tuesday, April 2026 Edition
blogs_krebs·2026-04-14·CVSS 6.5
CVE-2026-3220 [MEDIUM] Patch Tuesday, April 2026 Edition
Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed “ BlueHammer .” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited flaw that can lead to remote code execution.
Redmond warns that attackers are already targeting CVE-2026-32201 , a vulnerability in Microsoft SharePoint Server that allows attackers to spoof trusted content or interfaces over a network.
Mike Walters , president and co-founder of Action1 , said CVE-2026-32201 can be used to deceive employees, partners, or customers by presenting falsified information withi
Bleepingcomputer
Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
blogs_bleepingcomputer·2026-04-13·CVSS 8.6
CVE-2026-34621 [HIGH] Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
## Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
## Bill Toulas
Adobe has released an emergency security update for Acrobat Reader to fix a vulnerability, tracked as CVE-2026-34621, that has been exploited in zero-day attacks since at least December.
The flaw allows malicious PDF files to bypass sandbox restrictions and invoke privileged JavaScript APIs, potentially leading to arbitrary code execution. The exploit observed in attacks enables reading and stealing arbitrary files. No user interaction is required beyond opening the malicious PDF.
Specifically, the exploit abuses APIs like util.readFileIntoStream() to read arbitrary local files and RSS.addFeed() to exfiltrate data and fetch additional attacker-controlled code.
The security issue was discovered by Haifei
Hackernews
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
blogs_hackernews·2026-04-13·CVSS 8.6
[HIGH] ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a full-blown incident response is basically non-existent.
The variety this week is particularly nasty. We have AI models being turned into autonomous exploit engines, North Korean groups playing the long game
Hackernews
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
blogs_hackernews·2026-04-12·CVSS 9.6
CVE-2026-34621 [CRITICAL] Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
Adobe has released emergency updates to fix a critical security flaw in Acrobat Reader that has come under active exploitation in the wild.
The vulnerability, assigned the CVE identifier CVE-2026-34621 , carries a CVSS score of 8.6 out of 10.0. Successful exploitation of the flaw could allow an attacker to run malicious code on affected installations.
It has been described as a case of prototype pollution that could result in arbitrary code execution. Prototype pollution refers to a JavaScript security vulnerability that permits an attacker to manipulate an
2026-04-11
Published
2026-04-13
Added to CISA KEV
Exploited in the wild