Adobe Patches Actively Exploited Acrobat Reader Zero-Day CVE-2026-34621 — CISA Orders Federal Patch by April 27
A prototype pollution flaw in Acrobat Reader's JavaScript engine has been exploited in the wild since December 2025. CISA added it to the KEV catalog April 13 — patch immediately.
Adobe shipped an emergency out-of-band patch on April 12 for CVE-2026-34621, a prototype pollution vulnerability in Acrobat Reader’s JavaScript engine exploited in the wild since at least December 2025. CISA added it to its Known Exploited Vulnerabilities catalog on April 13; federal agencies have until April 27 to patch.
What the vulnerability does
A specially crafted PDF containing malicious JavaScript can trigger a prototype pollution chain that escalates to arbitrary code execution with the privileges of the current user. No user interaction beyond opening the file is required when Enhanced Protected Mode is disabled — the default for most enterprise deployments.
Affected versions
- Adobe Acrobat DC and Acrobat Reader DC 26.001.21367 and earlier
- Adobe Acrobat 2024 and Acrobat Reader 2024 24.001.30356 and earlier
CVSS score: 8.6 (High). Acrobat 2020 reached end-of-life in April 2024 and will not receive a patch — users on that version are running an unpatched attack surface.
Fixed versions
- Acrobat DC → 26.001.21411
- Acrobat 2024 → 24.001.30362 (Windows), 24.001.30360 (macOS)
Who is at risk
Initial telemetry from Qualys and Google GTIG points to targeted spear-phishing campaigns rather than mass opportunistic exploitation. The primary targets so far: legal, finance, and government recipients. The December 2025 exploitation start date is significant — some organizations were silently compromised for four months before a public patch existed.
The attack chain is straightforward: malicious PDF arrives via email, recipient opens it in Acrobat with default settings, JavaScript executes, attacker gains code execution. No sandbox escapes required beyond the prototype pollution chain itself.
What to do right now
- Open Acrobat or Reader → Help → Check for Updates and install 26.001.21411 (DC) or 24.001.30362 (2024 on Windows).
- Enterprise deployments on SCCM, Intune, or Jamf: push the update now, do not wait for the next scheduled cycle.
- Enable Enhanced Protected Mode as a mitigation layer: Edit → Preferences → Security (Enhanced) → Enable Protected Mode at startup.
- If still on Acrobat 2020, treat every PDF from an external sender as untrusted and upgrade immediately.
- If on macOS, target version is 24.001.30360 — confirm it matches before closing the ticket.
Adobe PDF software runs on hundreds of millions of endpoints. A four-month exploitation window, a CISA KEV listing, and a CVSS 8.6 score make this a same-day patch — not a next-cycle item.
The next regular Acrobat update is scheduled for May. This patch is available now through Help → Check for Updates.
Related reading
- Cybersecurity CVE-2026-42897 (CVSS 8.1): Microsoft Exchange OWA Zero-Day Actively Exploited — No Patch Available
- Cybersecurity CISA Adds 8 Actively Exploited Flaws to KEV, Including Three Cisco SD-WAN Zero-Days
- Cybersecurity Fortinet Ships Emergency Patch for Actively Exploited FortiClient EMS Zero-Day CVE-2026-35616 (CVSS 9.1)