← Intelligence Center
Intelligence Center
Adobe Acrobat Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-34621)
CVEs
CVE-2026-34621
Products
- •Acrobat DC versions 26.001.21367 and earlier
- •Acrobat Reader DC versions 26.001.21367 and earlier
- •Acrobat 2024 versions 24.001.30356 and earlier
Executive Summary
MS-ISAC Advisory 2026-033 (issued 4/11/2026): a vulnerability in Adobe Acrobat could allow for arbitrary code execution in the context of the logged-on user. The flaw is an Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) issue; exploitation requires user interaction, as a victim must open a malicious file. Adobe is aware of this vulnerability being exploited in the wild.
Municipal Impact
MS-ISAC rates the risk as Medium for large, medium, and small government entities, so municipal organizations running Adobe Acrobat should patch promptly.
SMB Impact
MS-ISAC rates the risk as Medium for large, medium, and small business entities and Low for home users.
Recommended Actions
- Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing.
- Apply the principle of least privilege to all systems and services and run software as a non-privileged user.
- Follow CIS Safeguards for vulnerability management, automated application patch management, and remediation.
Grey Matter Analysis
Analysis pending review.
References
- https://learn.cisecurity.org/e/799323/CVERecord-id-CVE-2026-34621/4vvkt8/2670573667/h/Yy8BQpYw04Vs1PPTmIqCrzpuLIkQf6oMtOJs6Rq87Is
- https://learn.cisecurity.org/e/799323/roducts-acrobat-apsb26-43-html/4vvkt5/2670573667/h/Yy8BQpYw04Vs1PPTmIqCrzpuLIkQf6oMtOJs6Rq87Is
- https://learn.cisecurity.org/e/799323/resources--type-advisory/4vvksc/2670573667/h/Yy8BQpYw04Vs1PPTmIqCrzpuLIkQf6oMtOJs6Rq87Is
Tags
Related Intelligence
Get Help
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter