CVE-2026-34621 is a prototype pollution vulnerability affecting Adobe Acrobat Reader versions 24.001.30356, 26.001.21367, and earlier. This flaw allows attackers to manipulate object prototype attributes, potentially enabling arbitrary code execution with the privileges of the current user. The vulnerability carries a CVSS score of 8.6 (HIGH), indicating significant risk. Attack requirements are minimal, as the flaw requires only local access and user interaction; specifically, a victim must open a malicious PDF file. Once exploited, the impact is severe, compromising confidentiality, integrity, and availability through code execution in the user's context. This vulnerability is actively exploited in the wild according to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating real-world threat activity. The FAUCET risk score of 86.0/100 reflects the high threat level, though the vulnerability is not currently on Adobe's hot list for immediate patching priorities. Organizations should prioritize patching affected Acrobat Reader versions and implement controls to prevent users from opening untrusted PDF files.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 26.001.21367CPE match | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
< 26.001.21411CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
< 26.001.21411CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* | ||
>= 24.0.0, < 24.001.30362CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
>= 24.0.0, < 24.001.30360CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.