Actively exploited prototype pollution flaw in Adobe Acrobat Reader patched as CVE-2026-34621
Summary
Hide ▲
Show ▼
A critical prototype pollution vulnerability in Adobe Acrobat Reader, tracked as CVE-2026-34621, has been patched following active in-the-wild exploitation. The flaw permits arbitrary code execution via malicious PDF documents containing crafted JavaScript, enabling attackers to compromise vulnerable systems. Exploitation has been observed since at least December 2025, with reports indicating abuse of the bug in targeted attacks. Adobe released emergency updates on April 12, 2026, after researchers publicly disclosed exploitation details and technical impact.
Timeline
-
12.04.2026 07:25 1 articles · 4h ago
Emergency patch issued for CVE-2026-34621 following active exploitation
Adobe released emergency updates on April 12, 2026, addressing CVE-2026-34621 in Acrobat Reader and Acrobat DC/2024, after researchers reported active in-the-wild exploitation dating to December 2025. The patched versions mitigate prototype pollution leading to arbitrary code execution via malicious PDFs containing crafted JavaScript.
Show sources
- Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 — thehackernews.com — 12.04.2026 07:25
Information Snippets
-
CVE-2026-34621 is a prototype pollution vulnerability in Adobe Acrobat Reader and Acrobat DC affecting Windows and macOS systems.
First reported: 12.04.2026 07:251 source, 1 articleShow sources
- Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 — thehackernews.com — 12.04.2026 07:25
-
Successful exploitation allows arbitrary code execution through malicious PDF documents leveraging crafted JavaScript payloads.
First reported: 12.04.2026 07:251 source, 1 articleShow sources
- Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 — thehackernews.com — 12.04.2026 07:25
-
Adobe patched the flaw in Acrobat DC 26.001.21411, Acrobat Reader DC 26.001.21411, Acrobat 2024 24.001.30362 (Windows) / 24.001.30360 (macOS), and earlier versions.
First reported: 12.04.2026 07:251 source, 1 articleShow sources
- Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 — thehackernews.com — 12.04.2026 07:25
-
Exploitation has been detected in the wild since at least December 2025, with public disclosure of active abuse occurring in early April 2026.
First reported: 12.04.2026 07:251 source, 1 articleShow sources
- Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 — thehackernews.com — 12.04.2026 07:25