CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerability
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Other sources
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34621?
The severity of CVE-2026-34621 is categorized as high due to potential prototype pollution vulnerabilities in Adobe Acrobat Reader.
How do I fix CVE-2026-34621?
To fix CVE-2026-34621, update Adobe Acrobat Reader to the latest version that is not vulnerable, specifically version 26.001.21411 or later.
What versions of Adobe Acrobat Reader are affected by CVE-2026-34621?
Adobe Acrobat Reader versions up to and including 26.001.21367 are affected by CVE-2026-34621.
What type of vulnerability is CVE-2026-34621?
CVE-2026-34621 is classified as an Improperly Controlled Modification of Object Prototype Attributes, also known as Prototype Pollution.
Is Adobe Acrobat DC affected by CVE-2026-34621?
Yes, Adobe Acrobat DC versions below 26.001.21411 are also impacted by CVE-2026-34621.