Adobe has issued an emergency patch for a critical, in-the-wild exploited prototype pollution vulnerability (CVE-2026-34621, CVSS 8.6) in Acrobat Reader that allows for arbitrary code execution via JavaScript manipulation.
Adobe has pushed out an emergency security update for Adobe Acrobat Reader, patching a zero-day vulnerability (CVE-2026-34621) exploited in the wild since November 2025. About CVE-2026-34621 CVE-2026-34621 is a critical prototype pollution vulnerability – a type of vulnerability that occurs in JavaScript and allows attackers to add or modify an application’s JavaScript objects and properties. CVE-2026-34621 can lead to arbitrary code execution in the context of the current user, but it cannot be triggered remotely. … More → The post Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621) appeared first on Help Net Security .