CVE-2026-34621
Sfruttamento noto · CISA KEV
CVSS 8.6 HIGH: acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification… EPSS 2% (82º percentile).
Data di correzione federale CISA 27 apr
Vulnerabilità ed exploit · Exploit zero-day
A prototype-pollution flaw in Adobe's PDF processing stack allows attackers to execute arbitrary code by delivering malicious PDFs. This breaks the assumption that PDF readers are low-risk utilities since opening a crafted document in common email or file-sharing workflows can lead to full compromise. The standard patching response misses that the delivery vector is everyday business communication, expanding the blast radius beyond just the Acrobat process.
Adobe confirmed active exploitation of CVE-2026-34621 since December 2025, prompting emergency patches for Acrobat DC, Acrobat Reader DC, and Acrobat 2024 on both Windows and macOS. The vulnerability involves JavaScript object manipulation within PDFs, enabling remote code execution. Affected versions include Acrobat DC and Reader DC up to 26.001.21367 and Acrobat 2024 up to 24.001.30356, with fixes in 26.001.21411 and 24.001.30362/30360 respectively.
This vulnerability shows attackers leveraging JavaScript prototype pollution rather than memory corruption, allowing exploitation across multiple OS builds. The risk extends to any user opening untrusted PDFs, making email and document workflows a critical attack surface. The broad deployment of affected Adobe products means this flaw poses an immediate and widespread threat requiring urgent patching.
5 fonti · 15 apr
Threat researchers reported Adobe’s Acrobat/Reader zero-day as actively exploited before the advisory, with malicious PDFs triggering JavaScript-driven code execution; SecurityWeek later noted Adobe downgraded severity to high, but patch urgency remains unchanged.
Sfruttamento noto · CISA KEV
CVSS 8.6 HIGH: acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification… EPSS 2% (82º percentile).
Data di correzione federale CISA 27 apr
JPCERT/CC
Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)
JPCERT-AT-2026-0011 JPCERT/CC 2026-04-15 Adobe Incorporated Security update available for Adobe Acrobat Reader | APSB26-44 https://helpx.adobe.com/security/products/acrobat/apsb26-44.html - Adobe Acrobat DC Continuous (26.001.21411) and earlier (Windows, macOS) - Adobe Acrobat…
originaleSecurityWeek
Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities
The security defects allow attackers to escalate privileges and execute arbitrary code remotely.
originaleBleepingComputer
Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
Adobe has released an emergency security update for Acrobat Reader to fix a vulnerability, tracked as CVE-2026-34621, that has been exploited in zero-day attacks since at least December.
originalePart of the PlainSec briefing for 2026-04-12
Every edition of this story: Malicious PDFs Enable Code Execution Across Windows and macOS