logo

Adobe Acrobat Reader CVE-2026-34621: Active exploitation via prototype pollution

ID: d55e4034-8bf5-5167-8344-c56ee20e782f

STIX ID: report--d55e4034-8bf5-5167-8344-c56ee20e782f

Feed Name: ThreatLocker Blog

Threat Score
80/100

Date Published: 2026-04-23

Date Updated: 2026-05-01

...
...

Executive summary: CVE-2026-34621 is a critical (CVSS 8.6) prototype-pollution vulnerability in Adobe Acrobat/Reader exploited in the wild via malicious PDFs that embed heavily obfuscated JavaScript to perform sandbox escape, system fingerprinting, RCE and covert RSS-based data exfiltration; the report provides a step-by-step technical analysis of the exploit chain, environment checks, payload delivery method, cleanup behavior, and supplies IOCs (file hashes and attacker-controlled IPs) and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.