EXPOSURES › CVE-2026-34621
CVE-2026-34621
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 85/100
rceexploited-in-wildransomwaresupply-chainunpatched
Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.
This prototype pollution vulnerability enables remote code execution in Adobe Acrobat and Reader, which are widely deployed in defense environments. DIB organizations must immediately patch and audit their Acrobat installations to prevent ransomware or espionage entry points.
Shame score — Active exploitation of a high-severity RCE vulnerability in a ubiquitous DIB tool indicates a critical security gap.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
AFFECTED FEDRAMP PRODUCTS · 8
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |