Executive brief
Adobe Acrobat and Reader, widely used applications for viewing and editing PDF documents, are affected by a critical security flaw. An attacker can exploit this vulnerability to take control of a user's computer if the user opens a specially crafted malicious file. This vulnerability is reportedly being used in active attacks, making immediate updates essential to protect sensitive data and system integrity.
Technical details
This vulnerability (CWE-1321) is caused by the improperly controlled modification of object prototype attributes, commonly known as prototype pollution, within the Adobe Acrobat and Reader JavaScript engine. An attacker can exploit this by delivering a malicious PDF file that, when opened by a victim, modifies the application's base object structure to execute arbitrary code in the context of the current user. The attack requires local file access and user interaction (opening the file). Adobe has released security updates (APSB26-43) to address this issue, which is confirmed to be exploited in the wild.
Affected products
- Adobe Acrobat 24.001.30356 and earlier, 26.001.21367 and earlier
- Adobe Acrobat Reader 24.001.30356 and earlier, 26.001.21367 and earlier
Timeline
- 2026-04-11: disclosed: Initial NVD publication
- 2026-04-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-04-13: patched: Vendor advisory APSB26-43 released