CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerability
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
How it works
CWE-1321 prototype pollution occurs when attacker-controlled input modifies the prototype of base JavaScript objects. In Adobe Acrobat and Reader this can be abused to alter application behavior and achieve arbitrary code execution.
Attackers supply crafted input that pollutes object prototypes, changing how subsequent code resolves properties and methods. The precise input vectors and triggering conditions must be confirmed against the vendor advisory.
Am I affected? How to find it in your systems
Adobe Acrobat and Reader run primarily on Windows and macOS workstations and servers used for PDF viewing and document workflows. Inventory all managed and unmanaged systems for these applications.
- Use endpoint management platforms, software inventory tools, or configuration management databases to locate installations of Adobe Acrobat and Reader.
- Identify the exact versions and any enabled JavaScript or PDF processing features, then compare them to the affected configurations listed in the vendor advisory.
- Review telemetry for anomalous child processes, unexpected JavaScript execution within the Acrobat sandbox, or unusual file-handling behavior that could indicate exploitation attempts.
How to remediate
Apply the vendor-supplied update referenced in the Adobe security advisory. Specific build numbers and deployment instructions must be verified directly from that advisory.
- Deploy the patched Acrobat and Reader packages through standard software distribution channels.
- Apply applicable CISA BOD 22-01 guidance for any cloud-hosted instances of the product.
- After patching, re-scan endpoints to confirm the vulnerable versions are no longer present.
If you can't patch immediately
Until the update can be applied, reduce exposure with the following controls.
- Segment networks so that systems running Adobe Acrobat and Reader are isolated from untrusted sources and high-value assets.
- Disable JavaScript execution inside PDF documents through application preferences where business requirements permit.
- Apply virtual patching or application control rules that block unexpected code paths associated with this weakness class.
- Discontinue use of the affected product if no mitigations can be implemented, consistent with CISA guidance.
If your data may have been exposed
Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H