CVE-2026-34621
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 7.09%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-1321
- Published
- 2026-04-11
- Last modified
- 2026-08-27
Affected products
- Adobe Acrobat Reader
- Adobe Acrobat DC
- Adobe Acrobat DC
- Adobe Acrobat Reader DC
- Adobe Acrobat Reader DC
- Adobe Acrobat 2024
- Adobe Acrobat 2024
Weakness type
Related vulnerabilities
- CVE-2026-89011 — isomorphic-git < 1.42.0 Prototype Pollution via getRemoteInfo
- CVE-2026-86078 — n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
- CVE-2026-81994 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
- CVE-2026-85625 — sift 17.1.3 Prototype Pollution Remote Code Execution via $where
- CVE-2026-63376 — toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
- CVE-2026-85063 — node-csv: Prototype replacement still reachable via columns path
- CVE-2026-82404 — TOON: Prototype pollution when decoding untrusted TOON input
- CVE-2026-84368 — joi: Prototype pollution via a `__proto__` language key in custom messages