VulnerabilitiesMay 15, 2026
‼️ CVE-2026-34621: Adobe Acrobat 2026 Prototype Pollution & JS Injection Chain GitHub: https...
CVE-2026-34621 discloses prototype pollution and JavaScript injection chain in Adobe Acrobat 2026.
Vendor Watch
Run Adobe?
Get an email when a reviewed story names Adobe, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
A new vulnerability (CVE-2026-34621) has been disclosed affecting Adobe Acrobat 2026, combining prototype pollution with JavaScript injection into a dangerous attack chain. Technical details and proof-of-concept code have been published on GitHub, along with a detailed write-up. This represents a critical flaw allowing arbitrary code execution through PDF manipulation.
Indicators of Compromise
- cve — CVE-2026-34621
Entities
Adobe Acrobat 2026 (product)Adobe (vendor)