Adobe Patches Acrobat Reader Zero-Day Vulnerability Exploited in the Wild

Adobe has rolled out an urgent security update to patch a critical zero-day vulnerability actively exploited in the wild, impacting Adobe Acrobat and Acrobat Reader for Windows and macOS systems.

The update, released under security bulletin APSB26-43 on April 11, 2026, fixes a flaw tracked as CVE-2026-34621, which allows attackers to execute arbitrary code on vulnerable systems.

Critical Vulnerability Overview

According to Adobe, the vulnerability is caused by an improperly controlled modification of object prototype attributes (CWE-1321), a type of Prototype Pollution issue.

This bug can be exploited by maliciously crafted PDF documents that, when opened in a vulnerable version of Acrobat Reader or Acrobat DC, can enable attackers to run arbitrary code with the privileges of the logged-in user.

The flaw has been rated critical with a CVSS base score of 8.6 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), indicating that local attack vectors combined with minimal user interaction are enough for successful exploitation.

Adobe confirmed that this vulnerability is already being actively exploited in the wild, making immediate patching essential.

Affected Software Versions

The security flaw affects the following product versions on both Windows and macOS:

  • Acrobat DC Continuous Track: 26.001.21367 and earlier
  • Acrobat Reader DC Continuous Track: 26.001.21367 and earlier
  • Acrobat 2024 Classic Track: 24.001.30356 and earlier

Users and enterprise administrators are advised to upgrade to the patched versions to mitigate the threat:

  • Acrobat and Reader DC (Continuous Track): 26.001.21411
  • Acrobat 2024 Classic Track: Windows (24.001.30362) | macOS (24.001.30360)

Security researcher Haifei Li from EXPMON is credited with discovering CVE-2026-34621. EXPMON has a strong track record of uncovering high-impact zero-days frequently weaponized in targeted attacks.

While Adobe has not disclosed detailed indicators of compromise or specific exploitation vectors, active exploitation reports suggest that attackers may be distributing malicious PDF lures designed to trigger vulnerability payloads upon opening.

Adobe classifies this update as Priority 1, signifying that the vulnerability is being exploited and that the update should be deployed as soon as possible.

Users can update through multiple methods:

  • Choose Help > Check for Updates within Acrobat or Reader.
  • Rely on automatic background updates, which many installations perform by default.
  • IT administrators can deploy patches using enterprise tools such as SCUP, SCCM, AIP-GPO, or Apple Remote Desktop.

This 0-day serves as another reminder of the persistent targeting of widely used PDF readers by threat actors.

Given Acrobat Reader’s large user base, exploited vulnerabilities in the software often translate into high-value attack opportunities.

Users and organizations are strongly urged to apply the latest updates immediately to block potential attacks and ensure continued protection.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories