LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2026
CVSS 8.6 · High⚠ Actively exploited (CISA KEV)
8.6
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-34621 to its Known Exploited Vulnerabilities catalog on Apr 13, 2026, with a federal patch deadline of Apr 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Adobe Acrobat and Reader contain a prototype pollution vulnerability that permits arbitrary code execution. The issue affects endpoints where these PDF applications are installed and requires inventory and remediation by IT and security teams to limit the risk of remote compromise.

How it works

CWE-1321 prototype pollution occurs when attacker-controlled input modifies the prototype of base JavaScript objects. In Adobe Acrobat and Reader this can be abused to alter application behavior and achieve arbitrary code execution.

Attackers supply crafted input that pollutes object prototypes, changing how subsequent code resolves properties and methods. The precise input vectors and triggering conditions must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader run primarily on Windows and macOS workstations and servers used for PDF viewing and document workflows. Inventory all managed and unmanaged systems for these applications.

How to remediate

Apply the vendor-supplied update referenced in the Adobe security advisory. Specific build numbers and deployment instructions must be verified directly from that advisory.

If you can't patch immediately

Until the update can be applied, reduce exposure with the following controls.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader
WeaknessCWE-1321
CVSS base score8.6 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
PublishedApr 11, 2026
Added to CISA KEVApr 13, 2026
Federal patch deadlineApr 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities