Adobe Rushes Emergency Patch for Acrobat Reader Zero-Day Under Active Attack
Want more insights like this?
Adobe released an emergency security patch for a critical zero-day vulnerability in Acrobat Reader that hackers are actively exploiting. The flaw, tracked as CVE-2026-34621, allows attackers to execute malicious code by tricking users into opening specially crafted PDF files.
The vulnerability stems from prototype pollution, where attackers can manipulate the application's underlying logic through malicious properties. It affects Acrobat Reader versions 24.001.30356, 26.001.21367, and earlier versions.
Threat actors are disguising malicious PDFs as legitimate business documents like invoices or legal records. Organizations should immediately apply Adobe's security updates and strengthen email filtering to block suspicious PDF attachments before they reach users.
Source: Cybersecurity News