Malicious PDFs Enable Code Execution Across Windows and macOS

A prototype-pollution flaw in Adobe's PDF processing stack allows attackers to execute arbitrary code by delivering malicious PDFs. This breaks the assumption that PDF readers are low-risk utilities since opening a crafted document in common email or file-sharing workflows can lead to full compromise. The standard patching response misses that the delivery vector is everyday business communication, expanding the blast radius beyond just the Acrobat process. Adobe confirmed active exploitation of CVE-2026-34621 since December 2025, prompting emergency patches for Acrobat DC, Acrobat Reader DC, and Acrobat 2024 on both Windows and macOS. The vulnerability involves JavaScript object manipulation within PDFs, enabling remote code execution. Affected versions include Acrobat DC and Reader DC up to 26.001.21367 and Acrobat 2024 up to 24.001.30356, with fixes in 26.001.21411 and 24.001.30362/30360 respectively. This vulnerability shows attackers leveraging JavaScript prototype pollution rather than memory corruption, allowing exploitation across multiple OS builds. The risk extends to any user opening untrusted PDFs, making email and document workflows a critical attack surface. The broad deployment of affected Adobe products means this flaw poses an immediate and widespread threat requiring urgent patching.

Part of the PlainSec briefing for 2026-04-14

Sources