Vulnerabilità ed exploit · Exploit zero-day

Malicious PDFs Enable Code Execution Across Windows and macOS

A prototype-pollution flaw in Adobe's PDF processing stack allows attackers to execute arbitrary code by delivering malicious PDFs. This breaks the assumption that PDF readers are low-risk utilities since opening a crafted document in common email or file-sharing workflows can lead to full compromise. The standard patching response misses that the delivery vector is everyday business communication, expanding the blast radius beyond just the Acrobat process.

Adobe confirmed active exploitation of CVE-2026-34621 since December 2025, prompting emergency patches for Acrobat DC, Acrobat Reader DC, and Acrobat 2024 on both Windows and macOS. The vulnerability involves JavaScript object manipulation within PDFs, enabling remote code execution. Affected versions include Acrobat DC and Reader DC up to 26.001.21367 and Acrobat 2024 up to 24.001.30356, with fixes in 26.001.21411 and 24.001.30362/30360 respectively.

This vulnerability shows attackers leveraging JavaScript prototype pollution rather than memory corruption, allowing exploitation across multiple OS builds. The risk extends to any user opening untrusted PDFs, making email and document workflows a critical attack surface. The broad deployment of affected Adobe products means this flaw poses an immediate and widespread threat requiring urgent patching.

5 fonti · 15 apr

Valutazione della community

Threat researchers reported Adobe’s Acrobat/Reader zero-day as actively exploited before the advisory, with malicious PDFs triggering JavaScript-driven code execution; SecurityWeek later noted Adobe downgraded severity to high, but patch urgency remains unchanged.

CVE-2026-34621

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.6 HIGH: acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification… EPSS 2% (82º percentile).

Data di correzione federale CISA 27 apr

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-14

Every edition of this story: Malicious PDFs Enable Code Execution Across Windows and macOS

Altro da oggi