Skip to content

// #pdf

1 article

🛡️ SecOps

Adobe Acrobat Reader Zero-Day CVE-2026-34621 Exploited for Four Months Before Patch

Adobe has released an emergency patch for CVE-2026-34621, a prototype pollution vulnerability in Acrobat Reader that has been actively exploited since at least November 2025. Opening a crafted PDF triggers JavaScript execution that fingerprints the victim's system and can deploy RCE and sandbox escape payloads. CISA added the CVE to the KEV catalogue the same day, requiring federal agencies to patch by 27 April.

#adobe +7