CVE-2026-34621
HIGH KEVAcrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Title source: cnaDescription
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Exploits (6)
github
NO CODE
1 stars
by Hex0rc1st · pythonpoc
https://github.com/Hex0rc1st/CVE_POC_monitor/tree/main/article/uploads/demo_1776061649/【在野利用】Adobe Acrobat Reader 远程代码执行漏洞(CVE-2026-34621)安全风险通告
nomisec
SUSPICIOUS
1 stars
by eduardorossi84 · poc
https://github.com/eduardorossi84/CVE-2026-34621-POC
nomisec
SCANNER
by KeulenR01 · poc
https://github.com/KeulenR01/Remediate-AdobeAcrobat-CVE-2026-34621
Scores
CVSS v3
8.6
EPSS
0.0760
EPSS Percentile
91.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Details
CISA KEV
2026-04-13
VulnCheck KEV
2026-04-07
ENISA EUVD
EUVD-2026-21675
CWE
CWE-1321
Status
published
Products (4)
adobe/acrobat
24.0.0 - 24.001.30362
adobe/acrobat_dc
< 26.001.21411
Adobe/Acrobat Reader
< 26.001.21367
adobe/acrobat_reader_dc
< 26.001.21411
Published
Apr 11, 2026
KEV Added
Apr 13, 2026
Tracked Since
Apr 11, 2026