What is CVE-2026-34621?
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Timeline
- 2026-04-11Published to the U.S. National Vulnerability Database (NVD)
- 2026-04-13First covered in a defend.network daily briefing
- 2026-04-13Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-04-27CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
Adobe Acrobat and Reader Prototype Pollution Vulnerability
Affected product
Adobe Acrobat And Reader
NVD also lists CPE entries for: Adobe Acrobat Dc, Adobe Acrobat Reader Dc, Adobe Acrobat, Apple Macos, Microsoft Windows
Remediation Steps
- Deploy Adobe Acrobat Reader emergency patch released April 2026 to all endpoints
- Implement application control to block execution of unpatched Reader versions
- Disable JavaScript execution in Adobe Reader as temporary mitigation if patching delayed
- Monitor for exploitation attempts using EDR/XDR tools with CVE-2026-34621 signatures
- Educate users against opening untrusted PDF attachments
References
- https://helpx.adobe.com/security/products/acrobat/apsb26-43.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34621
- https://www.adobe.com/security/security-bulletin
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-34621
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.