boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-34621

Adobe Acrobat DC — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  C  H  H  H    8.6   .0218   81.7   YES
AFFECTED
  Product            Versions     Fixed
  Acrobat DC         unspecified  26.001.21411
  Acrobat Reader DC  unspecified  26.001.21411
  Acrobat 2024       unspecified  24.001.30362 (Win), 24.001.30360 (Mac)
TIMELINE
  Mar 30  Reserved by adobe
  Apr 11  Published (CNA: adobe)
  Apr 13  Added to CISA KEV, remediation due 2026-04-27
  Aug 27  PATCH SHIPPED — CVE-2026-34621 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21411.
CWE-1321 · CNA: adobe · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due April 27, 2026

Description

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
March 30, 2026ReservedReserved by adobe
April 11, 2026PublishedPublished (CNA: adobe)
April 13, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-04-27
August 27, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-34621 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21411.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
AdobeAcrobat DC——26.001.21411
AdobeAcrobat Reader DC——26.001.21411
AdobeAcrobat 2024——24.001.30362 (Win), 24.001.30360 (Mac)

Weaknesses

CWE-1321

References (2)

Related

Authoritative record: CVE-2026-34621 at cve.org

Vendors: adobe

Weaknesses: CWE-1321

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-34621 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.