Critical Analysis: CVE-2026-34621 - Adobe Acrobat and Reader Prototype Pollution Vulnerability... — April 15, 2026
Published 15 Apr 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
Initial Discovery and Context Alright, let's talk about CVE-2026-34621. This one dropped on April 15, 2026, and it's a critical prototype pollution vulnerability affecting Adobe Acrobat and Reader. Specifically, it impacts versions 2023.003.20284 (Continuous Track) and earlier, and 2020.005.30510 (Classic Track) and earlier on Windows and macOS. When I first saw the preliminary disclosure, my immediate thought was "here we go again, another client-side vulnerability in a ubiquitous document viewer." The attack surface of PDF viewers, especially those with scripting capabilities, has always been massive. We've seen everything from JavaScript engine bugs to memory corruption issues over the years. This particular flavor, prototype pollution, isn't new territory for web browsers or Node.js environments, but seeing it manifest critically in a desktop application like Acrobat, particularly wi