← Back

CVE-2026-34621

nvd nist
Published: Apr 11, 2026Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 6.0
Source: psirt@adobe.com (Secondary)

Description

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected (4)

3 products
Acrobat Dc
Acrobat Reader Dc
Acrobat
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 26.001.21411
Before 26.001.21411
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 24.0.0 to 24.001.30362
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 24.0.0 to 24.001.30360
Running on/withPlatform Versions
Apple
Macos
All versions

References (2)

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.