Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34621

80
FAUCET Score

CVE-2026-34621 is a prototype pollution vulnerability affecting Adobe Acrobat Reader versions 24.001.30356, 26.001.21367, and earlier. This flaw allows attackers to manipulate object prototype attributes, potentially enabling arbitrary code execution with the privileges of the current user. The vulnerability carries a CVSS score of 8.6 (HIGH), indicating significant risk. Attack requirements are minimal, as the flaw requires only local access and user interaction; specifically, a victim must open a malicious PDF file. Once exploited, the impact is severe, compromising confidentiality, integrity, and availability through code execution in the user's context. This vulnerability is actively exploited in the wild according to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating real-world threat activity. The FAUCET risk score of 86.0/100 reflects the high threat level, though the vulnerability is not currently on Adobe's hot list for immediate patching priorities. Organizations should prioritize patching affected Acrobat Reader versions and implement controls to prevent users from opening untrusted PDF files.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 26.001.21367CPE match
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
< 26.001.21411CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
< 26.001.21411CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
>= 24.0.0, < 24.001.30362CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
>= 24.0.0, < 24.001.30360CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.09%
Probability of exploitation in next 30 days
EPSS Percentile
93.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Apr 13, 2026
This CVE's current EPSS score of 0.0709 is in the 93rd percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Patches (1)

adobevendor investigatingvia nvd_reference
View patch

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
helpx.adobe.com / security/products/acrobat/apsb26-43.html
Vendor Advisory