Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe’s April 11, 2026 security update fixes CVE-2026-34621, a critical Acrobat and Reader vulnerability that Adobe says attackers were exploiting in the wild. If your Windows or Mac installation is on an affected version, update it to the matching fixed version below.

What the Acrobat zero-day does

Adobe classifies CVE-2026-34621 as improper control of object prototype attribute modification, also known as “Prototype Pollution.” The stated impact is arbitrary code execution. Adobe’s bulletin rates it Critical and gives it a CVSS 3.1 base score of 8.6. Adobe revised the score from 9.6 to 8.6 on April 12, 2026, after changing its assessment of the attack vector from Network (AV:N) to Local (AV:L). The current bulletin rating is 8.6, not 9.6. Adobe credits Haifei Li of EXPMON for reporting the flaw. Adobe security bulletin APSB26-43

Adobe says in that bulletin: “Adobe is aware of CVE-2026-34621 being exploited in the wild.” Its Priority 1 designation makes applying the update especially urgent. The score describes the vulnerability’s severity; Adobe’s bulletin does not provide a victim count or estimate how many users are affected.

Is your Acrobat or Reader version affected?

Match your installed product, update track, version, and operating system to Adobe’s table. The version numbers are not interchangeable across tracks, so do not infer that a similar-looking version in another product line is affected or fixed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Adobe Acrobat 6 PDF For Dummies
  • Used Book in Good Condition
Product and track Affected versions Fixed version Platform
Acrobat DC, Continuous 26.001.21367 and earlier 26.001.21411 Windows and macOS
Acrobat Reader DC, Continuous 26.001.21367 and earlier 26.001.21411 Windows and macOS
Acrobat 2024, Classic 2024 24.001.30356 and earlier Windows: 24.001.30362
macOS: 24.001.30360
Windows and macOS

These affected and fixed versions are those listed in APSB26-43, published April 11 and updated April 12, 2026. Check Adobe’s bulletin and current release notes if you are applying the update later, as version information can change.

How to install the Adobe Acrobat zero-day patch

Update Acrobat or Reader from the app

  1. Open Acrobat or Acrobat Reader.
  2. Select Help > Check for Updates.
  3. Install the update if one is offered, then follow any prompts to restart or reopen the application.

Adobe also says to allow automatic updates to install when they are detected.

Rank #2
Adobe Acrobat Pro | PDF Software | Convert, Edit, E-Sign, Protect | PC/Mac Online Code | Activation Required
  • Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go.
  • Edit text and images without jumping to another app.
  • E-sign documents or request e-signatures on any device. Recipients don’t need to log in to e-sign.
  • Convert PDFs to editable Microsoft Word, Excel, or PowerPoint documents.
  • Share PDFs for collaboration. Commenting features make it easy for reviewers to comment, mark up, and annotate.

Download Reader’s full installer

If you need a full installer for Reader, use Adobe’s Download Center. Confirm that the installed product and track reach the corresponding fixed version in the table.

Update managed installations

Administrators should use the relevant Adobe release notes and their organization’s managed deployment method. Adobe lists AIP-GPO, bootstrapper, and SCUP/SCCM for Windows, and Apple Remote Desktop or SSH for macOS as example deployment methods. Consult Adobe’s APSB26-43 bulletin for the release-note direction and deployment details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep this patch separate from Adobe’s later bulletin

Adobe’s security index lists APSB26-141, published September 8, 2026, as a later Acrobat and Reader security update. It is a separate bulletin from APSB26-43. Adobe’s statement that it was not aware of in-the-wild exploits applies to the issues addressed in APSB26-141; it does not change Adobe’s statement that CVE-2026-34621 was exploited in the wild. Adobe PSIRT security bulletin index

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.