Technology

Adobe warns: Critical vulnerability in Acrobat

A critical security vulnerability threatens users of Adobe Acrobat on Windows and MacOS. Attackers are already actively exploiting the vulnerability to spread malware. However, an update is already available and protects against the far-reaching consequences.

Critical vulnerability threatens PDF users

PDF programs such as UPDF or Acrobat Reader are widely used. However, users of Adobe’s program for Windows and MacOS are currently exposed to a high security risk. Criminals exploit a vulnerability (CVE-2026-34621) is actively used to execute malicious code on the victims’ systems when opening prepared PDF documents and to install ransomware or programs to steal data. There is no need for user interaction beyond simply opening a file. Adobe has already provided a patch and recommends installing it immediately. The problem is technically based on a so-called “Prototype Pollution”. With such a vulnerability, attackers manipulate the properties of the application objects. Since Acrobat Reader is standard equipment in many company networks, the potential attack surface is enormous. IT departments should act quickly to protect networks from further infiltration.

Like Adobe in one Security Bulletin warns, the threat should be classified as critical. Security researchers report that attacks have been occurring since December 2025. For example, decoy documents in Russian are used that purport to contain information about the oil and gas industry.

Protection measures and updates

To protect yourself, users should install the patches provided immediately. The vulnerability affects the following versions of the software:

  • Acrobat DC – All versions before 26.001.21411
  • Acrobat Reader DC – All versions before 26.001.21411
  • Acrobat 2024 – All versions before 24.001.30362 (Windows)
  • Acrobat 2024 – All versions before 24.001.30360 (MacOS)

The update can be carried out directly in the program menu under “Help” > “Check for updates”. If you cannot install the update directly, you should take temporary protective measures. These include disabling JavaScript in Acrobat’s settings and opening file attachments in an isolated sandbox environment.

In addition, revoking local administrator rights for standard users is an effective protection. The Portable Document Format was originally developed in the early 1990s for platform-independent display. Today the format is a global standard for document exchange. The wide distribution makes reading and processing programs a lucrative target for hackers.

View Comments

Recent Posts

Multikernel Linux: Multiple Linux systems without a VM on one device

Multikernel Technologies has a public version of its multikernel Linux for the first time with…

1 day ago

Memory crisis makes you creative: New MSI laptop with DDR4 or DDR5

The world's PC manufacturers are in a bind when it comes to memory. DDR4 RAM…

1 day ago

Gamescom 2026: Series of thefts hit small indie developers hard

How safe are the protected halls of Gamescom 2026 really? After the night-time theft of…

1 day ago

GrapheneOS: No secure Android for the Pixel 11 because Google is sloppy?

Google has apparently made changes to the security features of the Pixel 11 series, which…

1 day ago

The Smart Girl’s Guide to Staying Safe Online While Shopping

Bagging a bargain online has never been easier - or riskier. Between dodgy "influencer" deals…

1 day ago

Google against website operators: AI overview in search even larger

Google is expanding its AI overviews and is now displaying even more information and details…

1 day ago