Adobe has released emergency updates for Acrobat and Acrobat Reader to address a critical zero‑day vulnerability (CVE-2026-34621) that is being actively exploited in the wild. The flaw is a JavaScript prototype pollution issue that can lead to arbitrary code execution and affects multiple Acrobat DC and Acrobat 2024 builds disclosed by EXPMON researcher Haifei Li. #CVE-2026-34621 #AdobeReader #EXPMON
Keypoints
- CVE-2026-34621 carries a CVSS score of 8.6 and can enable arbitrary code execution when exploited.
- The root cause is a JavaScript prototype pollution vulnerability that can be triggered by specially crafted PDFs.
- Affected products include Acrobat DC and Acrobat Reader DC up to 26.001.21367 and Acrobat 2024 up to 24.001.30356, with fixes in later builds.
- Adobe acknowledged active in-the-wild exploitation and issued emergency patches for Windows and macOS.
- Researcher Haifei Li and EXPMON disclosed the zero-day, with evidence suggesting exploitation may date back to December 2025 and Adobe later revised the CVSS and attack vector.
Read More: https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html