CVE-2026-34621
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2026-34621 is a Prototype Pollution vulnerability (CWE-1321) in Adobe Acrobat Reader and Acrobat DC that allows arbitrary code execution in the context of the current user. Affected versions include Acrobat Reader DC and Acrobat DC versions 26.001.21367 and earlier (Continuous track), and Acrobat Classic versions 24.001.30356 and earlier. The vulnerability was publicly disclosed on April 11, 2026, with Adobe releasing an emergency patch on April 11–13, 2026. It carries a CVSS v3.1 base score of 8.6 (High) per NVD, though ENISA rates it 9.6 (Critical) (Adobe Advisory, CISA KEV, Feedly).

Technical details

The vulnerability stems from improperly controlled modification of object prototype attributes (CWE-1321) within Adobe Acrobat Reader's JavaScript/eScript engine. By crafting a malicious PDF that injects properties into the base Object.prototype, an attacker can corrupt the application's internal object model and redirect execution flow to attacker-controlled code. Exploitation requires low attack complexity and no privileges, but does require a victim to open the malicious file. A technical deep-dive by STAR Labs described the exploit chain as involving three bugs, with prototype pollution serving as the entry point leading to a use-after-free condition enabling RCE (STAR Labs, Exodus Intel, HPE Threat Labs).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user, enabling full system compromise including data theft, malware installation, and lateral movement within a network. All three security pillars — confidentiality, integrity, and availability — are rated High impact. The STX malware family has been confirmed as weaponizing this vulnerability in targeted campaigns, and exploitation has been linked to espionage activity ongoing since at least December 2025 (Feedly, SecureBulletin, Forbes).

Exploitability

CVE-2026-34621 was actively exploited in the wild as a zero-day for approximately four months before patching, with exploitation confirmed as early as December 2025 (SecureBulletin). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on April 13, 2026, with a remediation due date of April 27, 2026 (CISA KEV). The EPSS score is approximately 0.0456 (4.56%). A GitHub repository (https://github.com/ercihan/CVE-2026-34621) exists but was assessed as containing only reverse-engineering notes without runnable exploit code; however, additional PoC repositories (e.g., eduardorossi84/CVE-2026-34621-POC, NULL200OK/cve_2026_34621_advanced) have appeared. The STX malware family has been confirmed as weaponizing this vulnerability (Feedly, The Hacker News).

Exploitation steps

  1. Reconnaissance: Identify targets using Adobe Acrobat Reader DC (≤26.001.21367) or Acrobat Classic (≤24.001.30356) via phishing target profiling or open-source intelligence.
  2. Craft malicious PDF: Create a PDF embedding JavaScript that exploits the prototype pollution flaw by injecting properties into Object.prototype via Acrobat's eScript/JavaScript API (e.g., Object.prototype.__proto__ manipulation or __defineGetter__ abuse).
  3. Deliver the payload: Send the malicious PDF to the victim via phishing email, malicious download link, or compromised website — the attack vector is local (file open), so social engineering is required to induce the victim to open the file.
  4. Trigger prototype pollution: When the victim opens the PDF, Acrobat's JavaScript engine processes the embedded script, corrupting the object prototype and triggering a use-after-free condition in the eScript API.
  5. Achieve code execution: The corrupted memory state redirects execution to attacker-controlled shellcode or a staged payload, executing arbitrary code in the context of the current user — enabling reverse shell, credential theft, or malware (e.g., STX) deployment (STAR Labs, Exodus Intel, Feedly).

Indicators of compromise

  • Network: Unexpected outbound connections from the Acrobat Reader process (AcroRd32.exe or Acrobat.exe) to unknown external IPs or C2 infrastructure; DNS queries to newly registered or suspicious domains initiated by the PDF reader process.
  • Process: Unusual child processes spawned by AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, wscript.exe, curl.exe); process injection into other running processes originating from the Acrobat process tree.
  • File System: Unexpected files dropped in %TEMP%, %APPDATA%, or user profile directories following PDF opening; new scheduled tasks or autorun registry entries created after PDF interaction; presence of STX malware artifacts.
  • Logs: Windows Event Logs showing process creation events (Event ID 4688) with Acrobat as parent and shell/scripting interpreters as children; Acrobat crash logs or JavaScript error logs indicating prototype manipulation attempts.
  • Email/Delivery: Phishing emails with PDF attachments targeting users of Adobe Acrobat Reader, particularly those with subject lines designed to induce urgency (Feedly, STAR Labs).

Mitigation and workarounds

Adobe released patched versions on April 11–13, 2026: update Adobe Acrobat Reader DC and Acrobat DC (Continuous) to version 26.001.21411 or later, and Adobe Acrobat Classic to version 24.001.30362 or later (Adobe Advisory). CISA mandated federal agencies apply mitigations by April 27, 2026 (CISA KEV). As interim workarounds: disable JavaScript execution in Adobe Acrobat (Edit → Preferences → JavaScript → uncheck "Enable Acrobat JavaScript"); configure email clients and browsers to not automatically open PDF files; and exercise caution when opening PDFs from untrusted sources. Organizations unable to patch immediately should consider blocking PDF execution via application allowlisting tools.

Community reactions

The vulnerability generated significant media and community attention given its zero-day status and months-long exploitation window. Forbes, The Hacker News, BleepingComputer, Dark Reading, The Register, TechCrunch, and SecurityWeek all covered the story prominently, with Forbes noting the attack had been "ongoing since 2025" (Forbes, The Register, BleepingComputer). STAR Labs published a detailed technical blog titled "Three Bugs Walk Into a PDF: Prototype Pollution Served Cold," revealing the multi-bug exploit chain (STAR Labs). The security community on Reddit (r/blueteamsec, r/netsec, r/cybersecurity) and Mastodon/Bluesky widely discussed the vulnerability, with some researchers noting that a purported PoC was actually a campaign weaponizer targeting Brazilian fintech (Reddit netsec). Malwarebytes highlighted that "simply opening a PDF could trigger this zero-day" (Malwarebytes).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management