
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34621 is a Prototype Pollution vulnerability (CWE-1321) in Adobe Acrobat Reader and Acrobat DC that allows arbitrary code execution in the context of the current user. Affected versions include Acrobat Reader DC and Acrobat DC versions 26.001.21367 and earlier (Continuous track), and Acrobat Classic versions 24.001.30356 and earlier. The vulnerability was publicly disclosed on April 11, 2026, with Adobe releasing an emergency patch on April 11–13, 2026. It carries a CVSS v3.1 base score of 8.6 (High) per NVD, though ENISA rates it 9.6 (Critical) (Adobe Advisory, CISA KEV, Feedly).
The vulnerability stems from improperly controlled modification of object prototype attributes (CWE-1321) within Adobe Acrobat Reader's JavaScript/eScript engine. By crafting a malicious PDF that injects properties into the base Object.prototype, an attacker can corrupt the application's internal object model and redirect execution flow to attacker-controlled code. Exploitation requires low attack complexity and no privileges, but does require a victim to open the malicious file. A technical deep-dive by STAR Labs described the exploit chain as involving three bugs, with prototype pollution serving as the entry point leading to a use-after-free condition enabling RCE (STAR Labs, Exodus Intel, HPE Threat Labs).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user, enabling full system compromise including data theft, malware installation, and lateral movement within a network. All three security pillars — confidentiality, integrity, and availability — are rated High impact. The STX malware family has been confirmed as weaponizing this vulnerability in targeted campaigns, and exploitation has been linked to espionage activity ongoing since at least December 2025 (Feedly, SecureBulletin, Forbes).
CVE-2026-34621 was actively exploited in the wild as a zero-day for approximately four months before patching, with exploitation confirmed as early as December 2025 (SecureBulletin). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on April 13, 2026, with a remediation due date of April 27, 2026 (CISA KEV). The EPSS score is approximately 0.0456 (4.56%). A GitHub repository (https://github.com/ercihan/CVE-2026-34621) exists but was assessed as containing only reverse-engineering notes without runnable exploit code; however, additional PoC repositories (e.g., eduardorossi84/CVE-2026-34621-POC, NULL200OK/cve_2026_34621_advanced) have appeared. The STX malware family has been confirmed as weaponizing this vulnerability (Feedly, The Hacker News).
Object.prototype via Acrobat's eScript/JavaScript API (e.g., Object.prototype.__proto__ manipulation or __defineGetter__ abuse).AcroRd32.exe or Acrobat.exe) to unknown external IPs or C2 infrastructure; DNS queries to newly registered or suspicious domains initiated by the PDF reader process.AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, wscript.exe, curl.exe); process injection into other running processes originating from the Acrobat process tree.%TEMP%, %APPDATA%, or user profile directories following PDF opening; new scheduled tasks or autorun registry entries created after PDF interaction; presence of STX malware artifacts.Adobe released patched versions on April 11–13, 2026: update Adobe Acrobat Reader DC and Acrobat DC (Continuous) to version 26.001.21411 or later, and Adobe Acrobat Classic to version 24.001.30362 or later (Adobe Advisory). CISA mandated federal agencies apply mitigations by April 27, 2026 (CISA KEV). As interim workarounds: disable JavaScript execution in Adobe Acrobat (Edit → Preferences → JavaScript → uncheck "Enable Acrobat JavaScript"); configure email clients and browsers to not automatically open PDF files; and exercise caution when opening PDFs from untrusted sources. Organizations unable to patch immediately should consider blocking PDF execution via application allowlisting tools.
The vulnerability generated significant media and community attention given its zero-day status and months-long exploitation window. Forbes, The Hacker News, BleepingComputer, Dark Reading, The Register, TechCrunch, and SecurityWeek all covered the story prominently, with Forbes noting the attack had been "ongoing since 2025" (Forbes, The Register, BleepingComputer). STAR Labs published a detailed technical blog titled "Three Bugs Walk Into a PDF: Prototype Pollution Served Cold," revealing the multi-bug exploit chain (STAR Labs). The security community on Reddit (r/blueteamsec, r/netsec, r/cybersecurity) and Mastodon/Bluesky widely discussed the vulnerability, with some researchers noting that a purported PoC was actually a campaign weaponizer targeting Brazilian fintech (Reddit netsec). Malwarebytes highlighted that "simply opening a PDF could trigger this zero-day" (Malwarebytes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."