Skip to content
COOEY

EXPOSURES › CVE-2026-34621

CVE-2026-34621

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-34621 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwaresupply-chainunpatched

Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.

This prototype pollution vulnerability enables remote code execution in Adobe Acrobat and Reader, which are widely deployed in defense environments. DIB organizations must immediately patch and audit their Acrobat installations to prevent ransomware or espionage entry points.

Shame score — Active exploitation of a high-severity RCE vulnerability in a ubiquitous DIB tool indicates a critical security gap.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized