← Intelligence Center

Adobe Acrobat Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-34621)

PublishedApr 11, 2026
Updated
VendorAdobe
SeverityMedium
Known ExploitedYes Known Exploited
Advisory IDINTEL-000013
CVEs
CVE-2026-34621
Products
  • Acrobat DC versions 26.001.21367 and earlier
  • Acrobat Reader DC versions 26.001.21367 and earlier
  • Acrobat 2024 versions 24.001.30356 and earlier

Executive Summary

MS-ISAC Advisory 2026-033 (issued 4/11/2026): a vulnerability in Adobe Acrobat could allow for arbitrary code execution in the context of the logged-on user. The flaw is an Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) issue; exploitation requires user interaction, as a victim must open a malicious file. Adobe is aware of this vulnerability being exploited in the wild.

Municipal Impact

MS-ISAC rates the risk as Medium for large, medium, and small government entities, so municipal organizations running Adobe Acrobat should patch promptly.

SMB Impact

MS-ISAC rates the risk as Medium for large, medium, and small business entities and Low for home users.

Recommended Actions

  1. Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing.
  2. Apply the principle of least privilege to all systems and services and run software as a non-privileged user.
  3. Follow CIS Safeguards for vulnerability management, automated application patch management, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter