CVE-2026-34622
8.6Adobe · Acrobat Reader
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows an attacker to execute arbitrary code when a user opens a malicious file.
Executive summary
Adobe Acrobat and Reader are vulnerable to an arbitrary code execution flaw caused by prototype pollution, which requires user interaction to trigger.
Vulnerability
This vulnerability is an improper control of object prototype attributes, commonly known as prototype pollution (CWE-1321). An unauthenticated attacker can achieve arbitrary code execution in the context of the current user by tricking them into opening a malicious file.
Business impact
The potential for arbitrary code execution poses a significant risk to organizational integrity, as it allows attackers to gain unauthorized control over local workstations. With a CVSS score of 8.6, this vulnerability is classified as high severity, as it can lead to full system compromise, data theft, and lateral movement within the network.
Remediation
Immediate Action: Update Adobe Acrobat and Reader to the fixed versions: 26.001.21431 for Acrobat DC and Reader DC, or 24.001.30365 for Acrobat 2024.
Proactive Monitoring: Monitor endpoint logs for suspicious child processes spawned by Acrobat or Reader, particularly those involving scripting engines or shell execution.
Compensating Controls: Deploy endpoint protection software to detect and block the execution of malicious documents, and enforce strict email filtering to prevent the delivery of suspicious PDF attachments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for arbitrary code execution, organizations should prioritize the deployment of the provided vendor patches. Security teams must ensure that all instances of Adobe Acrobat and Reader are updated across the enterprise to mitigate the risk of workstation compromise.