Summary
Adobe Acrobat DC, Acrobat Reader DC, and Acrobat 2024 on Windows and macOS contain a prototype pollution flaw in PDF object prototype handling. A crafted PDF can trigger arbitrary code execution when a victim opens the file in Acrobat or Reader, with code running as the current user. Adobe says the issue is being exploited in the wild.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary code as the current user
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Acrobat DC | 26.001.21367 and earlier |
| Acrobat Reader DC | 26.001.21367 and earlier |
| Acrobat 2024 | Windows: 24.001.30356 and earlier; macOS: 24.001.30360 and earlier |
Adobe Acrobat and Reader are desktop applications for viewing, creating, editing, annotating, and signing PDF documents.
Affected ComponentPDF document parsing and rendering when opening malicious files.
PDF document parsing and rendering when opening malicious files.
Not available
Not available
Update Acrobat DC and Acrobat Reader DC to 26.001.21411 or later, and Acrobat 2024 to 24.001.30362 (Windows) or 24.001.30360 (macOS) or later.
Update Acrobat DC and Acrobat Reader DC to 26.001.21411 or later, and Acrobat 2024 to 24.001.30362 (Windows) or 24.001.30360 (macOS) or later.
Probability of exploitation in the next 30 days
Worse than 46% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| helpx.adobe.com | Adobe Security Bulletin APSB26-43 |
| www.tenable.com | CVE-2026-34621 |
Priority History
Initial analysis