CVE-2026-34622
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2026-34622 is a Prototype Pollution vulnerability (CWE-1321) in Adobe Acrobat Reader and Acrobat DC that can result in arbitrary code execution in the context of the current user. Affected versions include Acrobat Reader DC and Acrobat DC versions 26.001.21411 and earlier (Continuous track), and Acrobat Classic versions 24.001.30360 and 24.001.30362 and earlier. Adobe disclosed and patched this vulnerability on April 14, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). This class of flaw allows an attacker to inject properties into JavaScript object prototypes within Acrobat's embedded scripting engine (eScript/JavaScript API), potentially overriding built-in behaviors and achieving arbitrary code execution. Exploitation requires local access in the sense that the victim must open a specially crafted malicious PDF file; no authentication or elevated privileges are required on the attacker's part. A detailed technical write-up by STAR Labs titled "Three Bugs Walk Into a PDF: Prototype Pollution Served Cold" provides in-depth analysis of the exploitation mechanics (STAR Labs Blog).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary code in the context of the current user, with high impact to confidentiality, integrity, and availability. Because the CVSS scope is marked as Changed, the vulnerability can affect resources beyond the Acrobat process itself, potentially enabling privilege escalation or lateral movement within the victim's environment. An attacker could use this to install malware, exfiltrate sensitive documents, or establish persistence on the compromised system (Adobe Advisory, STAR Labs Blog).

Exploitability

Exploitation has been reported in the wild according to multiple threat intelligence sources, including swecyb.com (swecyb.com). A proof-of-concept or exploit code reference has been noted on Vulners (Vulners), and the vulnerability was discussed in the context of May 2026 Patch Tuesday reviews (Reddit Action1). The EPSS score is approximately 0.235%, indicating a relatively low but non-negligible probability of exploitation in the near term. No specific threat actor attribution or CISA KEV catalog listing has been confirmed at this time.

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file containing embedded JavaScript that exploits prototype pollution in Acrobat's eScript engine — for example, by assigning properties to Object.prototype or Array.prototype to override internal Acrobat JavaScript behaviors.
  2. Deliver the payload: Distribute the malicious PDF via phishing email, malicious download link, or other social engineering vector targeting users of vulnerable Acrobat versions (≤26.001.21411 or ≤24.001.30362).
  3. Victim opens the file: The victim opens the PDF in a vulnerable version of Adobe Acrobat Reader or Acrobat DC, triggering execution of the embedded JavaScript.
  4. Prototype pollution triggers: The malicious JavaScript pollutes the prototype chain of a core JavaScript object within Acrobat's scripting engine, corrupting internal state or overriding security-relevant functions.
  5. Achieve code execution: The corrupted prototype state is leveraged to redirect execution flow, ultimately running attacker-controlled code in the context of the current user — potentially dropping a payload, establishing a reverse shell, or exfiltrating data (STAR Labs Blog, Exodus Intel Blog).

Indicators of compromise

  • File System: Unexpected files dropped in %TEMP%, %APPDATA%, or user profile directories shortly after opening a PDF; new or modified scheduled tasks or startup entries created by the Acrobat process.
  • Process: Unusual child processes spawned by AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, wscript.exe, curl.exe); Acrobat process making unexpected outbound network connections.
  • Network: Outbound connections from Acrobat processes to unknown or suspicious IP addresses/domains; DNS queries for unusual domains initiated by the Acrobat process.
  • Logs: Windows Event Logs showing process creation events (Event ID 4688) with AcroRd32.exe or Acrobat.exe as the parent process for shell or scripting interpreters; application crash logs or Dr. Watson entries associated with Acrobat around the time of suspicious activity.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: update Acrobat Reader DC and Acrobat DC (Continuous track) to version 26.001.21431 or later, and update Acrobat Classic to version 24.001.30365 or later (Adobe Advisory). Users should apply updates immediately via Adobe's built-in updater or through enterprise patch management tools. As interim mitigations, organizations should educate users about the risks of opening PDF files from untrusted sources, consider enabling Protected Mode/Protected View in Acrobat settings, and evaluate application sandboxing or whitelisting to restrict Acrobat's capabilities.

Community reactions

The CIS issued an advisory noting that multiple Adobe vulnerabilities patched in April 2026 could allow arbitrary code execution (CIS Advisory). Heise reported on the Adobe Patch Day, highlighting critical code execution vulnerabilities affecting Photoshop and other Adobe products including Acrobat (Heise). STAR Labs published a detailed technical blog post titled "Three Bugs Walk Into a PDF: Prototype Pollution Served Cold," which received community attention on Reddit's r/SecOpsDaily (Reddit SecOpsDaily). The Hacker News included this vulnerability in its weekly recap, and CyberSecurityNews covered the broader Adobe Acrobat Reader patch release (CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81996HIGH8.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesSep 08, 2026
CVE-2026-81997MEDIUM6.3
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesSep 08, 2026
CVE-2026-81994MEDIUM6.3
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
NoYesSep 08, 2026
CVE-2026-82001MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader
NoYesSep 08, 2026
CVE-2026-81993MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management