CVE-2026-34621: Adobe Acrobat and Reader Zero-Day Arbitrary Code Execution via Crafted PDF (Emergency Out-of-Band Patch)

CVE-2026-34621 (TL-2026-0354), also tracked as APSB26-18, is a critical-severity zero-day vulnerability scored CVSS 9.8, first published 2026-04-13. It has no confirmed attribution, affects Adobe Acrobat DC (Continuous), references 1 CVE (CVE-2026-34621), maps to 20 MITRE ATT&CK techniques (T1005, T1036, T1036.005), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0354

Threat ID
TL-2026-0354
Also known as
APSB26-18, Adobe Acrobat Reader PDF 0-day April 2026
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
ZERO_DAY
First published
2026-04-13
Last reviewed
2026-04-13
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
financial, legal, defense-industrial-base, government, technology, energy, healthcare
Target regions
North America, Europe, United Kingdom, Japan
Detection rules
9
Indicators of compromise
20

Malware and tooling in CVE-2026-34621

Malware and tooling: Custom HTTPS beacon (JSON over TLS 1.3)

Adobe released an emergency out-of-band security update for Adobe Acrobat and Acrobat Reader on Windows and macOS to address CVE-2026-34621, a critical use-after-free vulnerability in the PDF rendering engine that allows arbitrary code execution in the context of the current user when a victim opens a specially crafted PDF. The flaw is under active exploitation in targeted phishing campaigns delivering weaponized PDFs to enterprise mail users, and proof-of-concept code has surfaced in underground forums within hours of the advisory.

How CVE-2026-34621 works

CVE-2026-34621 is a critical client-side remote code execution vulnerability disclosed and patched out-of-band by Adobe on 2026-04-13. The flaw is rooted in a use-after-free condition in the JavaScript-to-AcroForm bridge of the PDF rendering engine shared by Adobe Acrobat and Adobe Acrobat Reader. When an attacker-supplied PDF triggers a crafted sequence of form field mutations while a referenced object is being garbage collected, the engine dereferences a stale pointer that the attacker controls via heap grooming, yielding full arbitrary code execution in the context of the process that opened the document.

Exploitation requires only that the victim open the malicious PDF; no further user interaction, sandbox escape gadget, or administrative privileges are needed to reach initial code execution. The attacker-delivered shellcode runs inside the Acrobat renderer process and, in the observed in-the-wild campaigns, immediately pivots out of the Reader Protected Mode sandbox using a second-stage broker abuse chain that exploits a previously-hardened but still exposed inter-process communication (IPC) endpoint. Post-exploitation, the attacker drops a loader to %APPDATA%\Adobe\Reader\ that establishes persistence via a Scheduled Task named "AdobeAcroUpdater" and beacons to HTTPS C2 infrastructure over 443.

Targeted phishing campaigns first observed by enterprise mail security vendors between 2026-04-02 and 2026-04-09 delivered the weaponized PDFs as attachments to invoices, contract negotiations, and HR onboarding lures, predominantly against finance, legal, and defense industrial base targets in North America and Europe. Adobe's Product Security Incident Response Team (PSIRT) was notified on 2026-04-05 by a combination of industry partners and an independent researcher; Adobe confirmed exploitation, accelerated a fix, and shipped APSB26-18 on 2026-04-13 as an out-of-band release, breaking the normal monthly cadence.

Adobe Acrobat DC, Acrobat 2020, Acrobat Reader DC, and Acrobat Reader 2020 are all affected on Windows and macOS. Linux is not affected because the vulnerable code path is not compiled into the Linux preview. CISA is expected to add CVE-2026-34621 to the Known Exploited Vulnerabilities (KEV) catalog within 24-48 hours of disclosure, which will make remediation mandatory for US Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive 22-01. Defenders should prioritize immediate patching, enablement of Protected View for all network and email-sourced PDFs, blocking of the known IOCs at the perimeter, and hunting for the persistence and C2 indicators listed in this report.

MITRE ATT&CK techniques used in TL-2026-0354

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1053.005 Scheduled Task; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204 User Execution; T1204.002 Malicious File

Command and Control

T1071 Application Layer Protocol; T1071.001 Web Protocols; T1573 Encrypted Channel; T1573.002 Asymmetric Cryptography

Discovery

T1082 System Information Discovery

Initial Access

T1566 Phishing; T1566.001 Spearphishing Attachment

Affected products and versions in CVE-2026-34621

  • Adobe — Acrobat DC (Continuous)
    Vulnerable versions: <= 26.004.30212
    Fixed in: 26.004.30215
  • Adobe — Acrobat Reader DC (Continuous)
    Vulnerable versions: <= 26.004.30212
    Fixed in: 26.004.30215
  • Adobe — Acrobat 2020 (Classic)
    Vulnerable versions: <= 20.005.30783
    Fixed in: 20.005.30786
  • Adobe — Acrobat Reader 2020 (Classic)
    Vulnerable versions: <= 20.005.30783
    Fixed in: 20.005.30786

Remediation for CVE-2026-34621

Patches

  • Adobe Acrobat DC and Reader DC: 26.004.30215 (Continuous Track)
  • Adobe Acrobat 2020 and Reader 2020: 20.005.30786 (Classic Track)
  • Adobe Security Bulletin APSB26-18 (out-of-band, released 2026-04-13)

Immediate actions

  • Apply Adobe Security Bulletin APSB26-18 immediately on all Windows and macOS endpoints running Acrobat or Acrobat Reader
  • Block the listed C2 domains and IPs at the web proxy, next-generation firewall, and DNS resolver (sinkhole where possible)
  • Enable Protected View for all files originating from the internet and email via GPO (HKLM\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms)
  • Temporarily disable JavaScript in Acrobat/Reader via bDisableJavaScript=1 until patch deployment completes
  • Quarantine PDF attachments at the email gateway pending deep content inspection
  • Hunt for the Scheduled Task named AdobeAcroUpdater and the loader file adobe_updater.dll in %APPDATA%\Adobe\Reader\

Workarounds

  • Disable JavaScript in Acrobat/Reader: Edit > Preferences > JavaScript > uncheck Enable Acrobat JavaScript
  • Enable Protected View in Standalone mode: Edit > Preferences > Security (Enhanced) > Files from potentially unsafe locations
  • Associate PDF file type with a non-Adobe reader (e.g., browser built-in viewer) until patch is applied
  • Block PDF attachments at the email gateway until remediation is complete

Longer-term hardening

  • Enforce Attack Surface Reduction (ASR) rule Block Office applications from creating child processes and extend equivalent AppLocker or WDAC policy to Acrobat/Reader renderer processes
  • Deploy EDR with behavioral rules for PDF readers spawning cmd.exe, powershell.exe, rundll32.exe, or wscript.exe
  • Require DMARC, DKIM, and SPF enforcement on inbound mail and strip or detonate PDF attachments in a sandbox before delivery
  • Standardize on the Adobe Acrobat Continuous Track and enforce minimum version via MDM/Intune
  • Implement phishing-resistant MFA (FIDO2) to reduce impact of credential theft following initial-access RCE
  • Conduct tabletop exercises and purple team drills using the TL-2026-0354 simulation pack

CVEs associated with CVE-2026-34621

CVE-2026-34621

Weaknesses (CWE) in CVE-2026-34621

CWE-416, CWE-787

Timeline of CVE-2026-34621

  • First weaponized PDF samples observed in the wild by enterprise mail security vendors targeting finance and legal sector recipients in North America
  • Adobe PSIRT formally notified by industry partners and an independent researcher after correlation of multiple samples to a shared exploitation primitive
  • Adobe confirms reproducible crash and code execution and begins emergency triage of the use-after-free in the JavaScript-to-AcroForm bridge
  • Targeted phishing campaign expands to defense industrial base and European government targets via contract-negotiation and HR-onboarding lures
  • Adobe completes internal regression testing on the fix and stages out-of-band builds for Continuous and Classic tracks
  • CISA publishes an emergency alert mirroring Adobe's advisory and signals imminent addition to the Known Exploited Vulnerabilities catalog
  • Public disclosure via SOCRadar and BleepingComputer; proof-of-concept chatter appears in underground forums within hours
  • Adobe releases emergency Security Bulletin APSB26-18 out-of-band for Windows and macOS, assigning CVE-2026-34621
  • As of 2026-05-29, CVE-2026-34621 is patched (Adobe out-of-band fix, 2026-04-13) and CISA KEV-listed with the FCEB deadline of 2026-04-27 now passed, but it remains actively exploited in the wild against unpatched endpoints with public PoC. It stays a live concern for the unpatched long tail, so MONITORING fits.

Sources cited for CVE-2026-34621

Threats related to CVE-2026-34621

Detection coverage for TL-2026-0354

As of 2026-04-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0354 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats