Adobe Patches Acrobat Zero-Day CVE-2026-34621 Exploited Since November 2025
A critical Acrobat Reader flaw quietly exploited since November 2025 forced an emergency patch, a CISA fix-by-date, and a public revision of its severity rating.
By Dillip Chowdary • Apr 13, 2026 • Source: BleepingComputer
Adobe shipped an out-of-band security update for Acrobat and Acrobat Reader in April 2026, fixing CVE-2026-34621 — a prototype-pollution flaw that researchers found had been actively exploited since November 2025, months before Adobe knew about it.
The bug surfaced after someone submitted a malicious PDF to EXPMON, a public file-exploit detection service; security researcher Haifei Li traced the sample back to CVE-2026-34621 and flagged it to Adobe.
Opening a booby-trapped PDF triggers prototype pollution in Acrobat's JavaScript engine, letting an attacker modify application objects and ultimately execute arbitrary code as the logged-in user — no network trigger required, just a user opening the file.
Adobe initially rated the flaw critical (CVSS 9.6) as though it were remotely triggerable, then revised the score down to 8.6 once it confirmed the attack vector is local (user interaction required) rather than network-based.
CISA added CVE-2026-34621 to its Known Exploited Vulnerabilities catalog on April 13, 2026, giving U.S. federal civilian agencies until April 27 to patch.
Fixed versions are Acrobat DC / Acrobat Reader DC 26.001.21411, and Acrobat 2024 versions 24.001.30362 and 24.001.30360 — anyone on an older build should update given the months-long window attackers already had before the fix shipped.