Adobe releases urgent security patch for Acrobat and Reader vulnerability

Adobe has released an urgent security update for Acrobat and Acrobat Reader to address a critical zero-day vulnerability. The company strongly advises all users to install the patch as soon as possible to prevent potential attacks.

The vulnerability, identified as CVE-2026-34621, affects Acrobat DC and Acrobat Reader DC versions earlier than 26.001.21367, as well as Acrobat 2024 versions prior to 24.001.30356. This issue has been found on both Windows and macOS platforms.

Classified as a Prototype Pollution flaw, it carries a high severity rating of 8.6 on the CVSS scale. This detail matters because it allows attackers to execute arbitrary code on a user's device, making it particularly dangerous.

Users with automatic updates enabled will receive the fix automatically. For others, the update can be installed manually through the program's menu or by downloading the latest version from Adobe's official website. In practice, this means ignoring the update is highly inadvisable, as zero-day vulnerabilities may already be actively exploited by malicious actors.