Recommended Free Tools
Adobe’s April 11, 2026 security update fixes CVE-2026-34621, a critical Acrobat and Reader vulnerability that Adobe says attackers were exploiting in the wild. If your Windows or Mac installation is on an affected version, update it to the matching fixed version below.
What the Acrobat zero-day does
Adobe classifies CVE-2026-34621 as improper control of object prototype attribute modification, also known as “Prototype Pollution.” The stated impact is arbitrary code execution. Adobe’s bulletin rates it Critical and gives it a CVSS 3.1 base score of 8.6. Adobe revised the score from 9.6 to 8.6 on April 12, 2026, after changing its assessment of the attack vector from Network (AV:N) to Local (AV:L). The current bulletin rating is 8.6, not 9.6. Adobe credits Haifei Li of EXPMON for reporting the flaw. Adobe security bulletin APSB26-43
Adobe says in that bulletin: “Adobe is aware of CVE-2026-34621 being exploited in the wild.” Its Priority 1 designation makes applying the update especially urgent. The score describes the vulnerability’s severity; Adobe’s bulletin does not provide a victim count or estimate how many users are affected.
Is your Acrobat or Reader version affected?
Match your installed product, update track, version, and operating system to Adobe’s table. The version numbers are not interchangeable across tracks, so do not infer that a similar-looking version in another product line is affected or fixed.
#1 Best Overall
| Product and track | Affected versions | Fixed version | Platform |
|---|---|---|---|
| Acrobat DC, Continuous | 26.001.21367 and earlier | 26.001.21411 | Windows and macOS |
| Acrobat Reader DC, Continuous | 26.001.21367 and earlier | 26.001.21411 | Windows and macOS |
| Acrobat 2024, Classic 2024 | 24.001.30356 and earlier | Windows: 24.001.30362 macOS: 24.001.30360 |
Windows and macOS |
These affected and fixed versions are those listed in APSB26-43, published April 11 and updated April 12, 2026. Check Adobe’s bulletin and current release notes if you are applying the update later, as version information can change.
How to install the Adobe Acrobat zero-day patch
Update Acrobat or Reader from the app
- Open Acrobat or Acrobat Reader.
- Select Help > Check for Updates.
- Install the update if one is offered, then follow any prompts to restart or reopen the application.
Adobe also says to allow automatic updates to install when they are detected.
Rank #2
- Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go.
- Edit text and images without jumping to another app.
- E-sign documents or request e-signatures on any device. Recipients don’t need to log in to e-sign.
- Convert PDFs to editable Microsoft Word, Excel, or PowerPoint documents.
- Share PDFs for collaboration. Commenting features make it easy for reviewers to comment, mark up, and annotate.
Download Reader’s full installer
If you need a full installer for Reader, use Adobe’s Download Center. Confirm that the installed product and track reach the corresponding fixed version in the table.
Update managed installations
Administrators should use the relevant Adobe release notes and their organization’s managed deployment method. Adobe lists AIP-GPO, bootstrapper, and SCUP/SCCM for Windows, and Apple Remote Desktop or SSH for macOS as example deployment methods. Consult Adobe’s APSB26-43 bulletin for the release-note direction and deployment details.
Rank #3
Keep this patch separate from Adobe’s later bulletin
Adobe’s security index lists APSB26-141, published September 8, 2026, as a later Acrobat and Reader security update. It is a separate bulletin from APSB26-43. Adobe’s statement that it was not aware of in-the-wild exploits applies to the issues addressed in APSB26-141; it does not change Adobe’s statement that CVE-2026-34621 was exploited in the wild. Adobe PSIRT security bulletin index
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

