Skip to content
Beveiligingsnieuws

CVE-2026-34621: Adobe Acrobat vulnerability

CVE-2026-34621

The NCSC has issued an alert about a highly severe vulnerability in Adobe Acrobat DC, Acrobat Reader DC, and Acrobat 2024. The vulnerability is named CVE-2026-34621 and the NCSC assigns a CVSS score of 9.6. It is also known that public exploit code is available, which increases the risk of large-scale attacks.

Because this software is widely used to open, create, and edit PDF files, it is important to take action now. In this article, we summarize what is going on and what you can do to quickly protect your systems against potential misuse.

What is CVE-2026-34621, and why is it urgent?

CVE-2026-34621 has been found in multiple Adobe products that are used every day to process digital documents. The NCSC describes the vulnerability as highly severe and reports that it is being actively exploited. This means attackers are likely using the weakness in the wild already, rather than it remaining only a theoretical risk.

An additional risk factor is that publicly available exploit code exists. With such code, malicious actors can prepare attacks faster, increasing the likelihood of harmful activity being deployed at scale. That is why the NCSC advises to carry out immediate updates.

How can exploitation take place?

According to the NCSC, an attacker can remotely execute malicious software on a user’s computer via a malicious PDF file. This can happen because the vulnerability allows actions to be carried out once the victim starts working with the infected document.

The impact can be serious. By exploiting it, the attacker may ultimately gain full control of the affected system. From an attacker’s perspective, this is a starting point for further steps, such as taking over data or setting up follow-on activities.

Potential impact for organizations

The NCSC lists multiple consequences that fit this type of attack. The vulnerability can lead to:

  • Data theft or the leakage of sensitive information
  • Loss of control over the computer by an attacker
  • Further spread of malware within an organization

For many organizations, it is especially concerning that PDFs are exchanged widely, both internally and externally. If an employee opens a document designed to abuse CVE-2026-34621, it may result in an immediate infection at workstation level.

What should you do now?

The NCSC’s core message is clear: implement security updates immediately. Adobe has released updates that fix the vulnerability. By installing those updates quickly, you reduce the chance that attacks succeed on systems that are still vulnerable.

1) Install the latest security updates

Check whether your systems run Adobe Acrobat DC, Acrobat Reader DC, or Acrobat 2024, and whether they have already been updated to the versions that patch the vulnerability. The NCSC recommends doing this as soon as possible.

2) Ask your IT service provider to verify which versions you use

Are you unsure whether you are using the relevant software or the exact versions? Contact your IT service provider. Ask them to help with rolling out updates and checking systems to make sure vulnerable variants are not left in place.

3) Be extra cautious with PDFs

Until the updates have been fully deployed, extra caution is advisable. Critically assess any received PDFs and watch for signs that may indicate misuse. While this does not replace patching the vulnerability, it can help reduce the inflow of malicious documents.

Why quick action pays off

Because CVE-2026-34621 is being actively exploited and public exploit code is available, the difference between “not yet” and “now” can be significant. The longer systems remain unchanged, the more likely it is that an attacker will reach vulnerable machines.

In addition, the impact can spread: if one endpoint is compromised, the NCSC says it can lead to further spread of malware within the organization. In other words, a fast update not only helps keep one device secure, but can also prevent a broader chain of incidents.

Conclusion

The NCSC warns about CVE-2026-34621 in Adobe Acrobat DC, Acrobat Reader DC, and Acrobat 2024. The vulnerability is highly severe (CVSS 9.6), is being actively exploited, and public exploit code is available. That makes immediate action necessary.

Install Adobe’s security updates as soon as possible and ask your IT service provider to check which versions are running in your environment. This will directly reduce the risk of data loss, system takeovers, and further malware spread.