Junglewise Threat Intelligence

CVE-2026-34621: Adobe Acrobat and Reader prototype pollution in JavaScript engine

CVE-2026-34621 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2026-04-11

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe Acrobat Reader, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader, widely used applications for viewing and editing PDF documents, are affected by a critical security flaw. An attacker can exploit this vulnerability to take control of a user's computer if the user opens a specially crafted malicious file. This vulnerability is reportedly being used in active attacks, making immediate updates essential to protect sensitive data and system integrity.

Technical details

This vulnerability (CWE-1321) is caused by the improperly controlled modification of object prototype attributes, commonly known as prototype pollution, within the Adobe Acrobat and Reader JavaScript engine. An attacker can exploit this by delivering a malicious PDF file that, when opened by a victim, modifies the application's base object structure to execute arbitrary code in the context of the current user. The attack requires local file access and user interaction (opening the file). Adobe has released security updates (APSB26-43) to address this issue, which is confirmed to be exploited in the wild.

Affected products

  • Adobe Acrobat 24.001.30356 and earlier, 26.001.21367 and earlier
  • Adobe Acrobat Reader 24.001.30356 and earlier, 26.001.21367 and earlier

Timeline

  • 2026-04-11: disclosed: Initial NVD publication
  • 2026-04-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-04-13: patched: Vendor advisory APSB26-43 released

Related threats