Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Adobe has released emergency updates for Acrobat and Acrobat Reader to address a critical zero‑day vulnerability (CVE-2026-34621) that is being actively exploited in the wild. The flaw is a JavaScript prototype pollution issue that can lead to arbitrary code execution and affects multiple Acrobat DC and Acrobat 2024 builds disclosed by EXPMON researcher Haifei Li. #CVE-2026-34621 #AdobeReader #EXPMON

Keypoints

  • CVE-2026-34621 carries a CVSS score of 8.6 and can enable arbitrary code execution when exploited.
  • The root cause is a JavaScript prototype pollution vulnerability that can be triggered by specially crafted PDFs.
  • Affected products include Acrobat DC and Acrobat Reader DC up to 26.001.21367 and Acrobat 2024 up to 24.001.30356, with fixes in later builds.
  • Adobe acknowledged active in-the-wild exploitation and issued emergency patches for Windows and macOS.
  • Researcher Haifei Li and EXPMON disclosed the zero-day, with evidence suggesting exploitation may date back to December 2025 and Adobe later revised the CVSS and attack vector.

Read More: https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html