logo

Adobe fixes actively exploited Acrobat Reader flaw CVE-2026-34621

ID: c93d872f-c890-5fa2-abfa-d4bb21ae2f8c

STIX ID: report--c93d872f-c890-5fa2-abfa-d4bb21ae2f8c

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-04-12

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Adobe released emergency updates for a critical, actively exploited Acrobat/Reader zero-day (CVE-2026-34621, CVSS 8.6). The flaw is a prototype pollution vulnerability enabling attackers to run malicious JavaScript from crafted PDFs to read local files, exfiltrate data, and potentially achieve remote code execution or sandbox escape on Windows and macOS; an EXPMON analyst reported sightings of a sample used in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.