Notable Vulnerabilities — 2026
A recurring interview question is "what recent vulnerabilities have caught your attention and why?" A good answer isn't a CVE-number recital — it's picking one or two that illustrate a trend and explaining the underlying class. 2026's standout theme: sandbox escapes via JavaScript engines — in document readers and, increasingly, in the JS sandboxes that AI agents use to run untrusted code.
Last verified2026-06. This file tracks current-year vulnerabilities for "what are you following lately?" interview questions. It's time-sensitive by design — details below are from public reporting/vendor advisories as of mid-2026; always confirm against the vendor advisory and NVD before acting.
CVE-2026-34621 — Adobe Acrobat/Reader "open a PDF → RCE" (prototype pollution)
The headline client-side bug of early 2026, and a great one to discuss because the exploit chain is elegant and the root cause is a web vulnerability class showing up in a desktop app.
What it isa prototype-pollution flaw in Adobe Acrobat's JavaScript engine (CVSS ~8.6) affecting Acrobat DC, Acrobat Reader DC, and Acrobat 2024. Acrobat embeds a JavaScript engine to run scripts inside PDFs (forms, validation, etc.), normally confined to a restricted, privileged API sandbox. This bug lets a malicious PDF corrupt that engine's object prototypes to reach privileged Acrobat JS APIs it shouldn't, escaping the sandbox to remote code execution — triggered just by opening the PDF, no further user interaction.
The exploit chain (why your "rss://" memory was close):
1. Victim opens a malicious PDF
2. Prototype pollution corrupts the JS engine → unlocks PRIVILEGED Acrobat JS APIs
3. util.readFileIntoStream() → read arbitrary LOCAL files off the victim's disk
4. RSS.addFeed() → (a) exfiltrate the stolen data to a C2 server, AND
(b) pull DOWN follow-on JavaScript to execute
5. → sandbox escape → arbitrary code execution on the hostThe thing you half-remembered as "rss://" is RSS.addFeed() — a privileged Acrobat JavaScript API (for adding RSS feeds), not a URL scheme. The attacker repurposed it as a bidirectional C2 channel: outbound exfil and inbound code delivery, all from inside a "sandboxed" PDF.
Timelineexploited in the wild since late 2025 (reports cite November/December 2025) as a zero-day, and Adobe shipped an emergency out-of-band patch in April 2026 (Acrobat/Reader DC 26.001.21411; Acrobat 2024 24.001.30362/30360).
Memory hook"prototype pollution turned a PDF into a remote shell." Two transferable lessons. (1) A sandbox is only as strong as the APIs it exposes — Acrobat's JS sandbox was bypassed not by breaking the VM but by corrupting object prototypes to reach privileged APIs that were always there. (2) Prototype pollution is a JavaScript vuln class (covered below) that people think of as a Node.js/web problem — but any embedded JS engine (Acrobat, Electron apps, AI agent sandboxes) inherits it. The detection takeaway: PDFs are code, and
RSS.addFeed/util.readFileIntoStream-style API calls plus a child process or outbound connection fromAcroRd32.exe/Acrobat.exeis the behavioral signature.
The 2026 trend: JavaScript sandbox escapes (especially in AI agents)
CVE-2026-34621 wasn't isolated — 2026 saw a wave of sandbox-escape RCEs in JavaScript execution environments, and a striking number target the sandboxes AI agents use to run model-generated or user-supplied code:
| CVE | Component | Note |
|---|---|---|
| CVE-2026-43999, CVE-2026-45411, CVE-2026-22709 | vm2 (Node.js sandbox) | Escapes to host RCE (one rated 9.9) by loading excluded Node builtins — and vm2 is widely embedded to "safely" run untrusted JS, including in AI agent tooling |
| CVE-2026-1470, CVE-2026-25049 | n8n (workflow automation) | Authenticated users escape the JS sandbox → RCE on the server |
| CVE-2026-27597 | Enclave (JS sandbox) | CVSS 10.0 RCE |
| CVE-2026-39888 | PraisonAI | Sandbox escape (CVSS 9.9) in an AI-agent framework |
| CVE-2026-34156 | NocoBase | Unrestricted module loading → RCE as root (CVSS 10) |
The connective tissue: organizations increasingly run untrusted code (from users, or generated by an LLM) inside a "safe" JavaScript sandbox — and 2026 repeatedly proved those sandboxes leak. Security researchers explicitly framed the vm2 wave as "turning AI agents into host RCE vectors."
Memory hook"the new RCE surface is the AI agent's code sandbox." This is the 2026 story to tell in an interview: as agents gain the ability to execute code (a tool call that runs JavaScript/Python in a sandbox), the sandbox becomes the trust boundary — and
vm2-class escapes turn "the model wrote some code" into "an attacker got RCE on the host." It directly extends the OWASP-LLM Excessive Agency lesson (seeai-security/owasp-llm-2025.md): you can't trust the model's output, so the sandbox must hold — and software sandboxes (vm2/Enclave) keep failing. The robust answer is the same as for LeetCode-judge untrusted-code: don't rely on an in-process JS sandbox; use a real isolation boundary — gVisor, a Firecracker microVM, or a disposable container with no network and dropped privileges (seekubernetes/fundamentals.md).
Refresher: Prototype Pollution (the vuln class behind CVE-2026-34621)
Worth knowing as a class because it keeps appearing. In JavaScript, objects inherit from a shared prototype (Object.prototype). If untrusted input can write to a special key like __proto__, an attacker can modify the prototype that every object inherits from — injecting or overwriting properties globally.
// Attacker-controlled merge/assign of untrusted JSON:
malicious = JSON.parse('{"__proto__": {"isAdmin": true}}')
merge(target, malicious)
// Now EVERY object may suddenly report isAdmin === true — or a corrupted property
// can be steered into a dangerous code path (as in the Acrobat privileged-API escape).auth bypass, DoS, and — when a polluted property reaches a sensitive sink (a function lookup, a privileged API) — RCE, which is exactly what happened in Acrobat.
validate/whitelist keys (reject __proto__, constructor, prototype), use Object.create(null) or Map for untrusted data, Object.freeze(Object.prototype), and keep JS engines patched.
Interview Questions
The 2026 Adobe Acrobat zero-day, CVE-2026-34621, because it's a clean illustration of a few things at once. The root cause is prototype pollution — a JavaScript vulnerability class people associate with Node.js, showing up in a desktop PDF reader's embedded JS engine. The exploit just needs the victim to open a PDF: prototype pollution corrupts the engine to reach privileged Acrobat APIs, then it uses util.readFileIntoStream to read local files and the RSS.addFeed API as a two-way C2 channel to exfiltrate data and pull down more code, escaping the sandbox to RCE. It was exploited in the wild for months before the April 2026 emergency patch. What makes it interesting beyond the bug is the trend it fits — 2026 had a whole wave of JavaScript sandbox escapes, many hitting the sandboxes AI agents use to run code, which reframes the agent's code sandbox as a new RCE surface.
Acrobat runs JavaScript embedded in PDFs, but confines it to a restricted set of APIs so a malicious PDF can't, say, read your files or run commands. A sandbox escape means breaking out of that confinement to reach capabilities you shouldn't have. Here it wasn't done by breaking the VM itself but by prototype pollution corrupting the engine's objects so the script could reach privileged APIs that already existed — reading local files and using RSS.addFeed for command-and-control. The lesson is that a sandbox is only as strong as the APIs it exposes and the integrity of the engine enforcing it: if attacker-controlled input can corrupt the engine's state to reach privileged functions, the sandbox boundary is moot. It's why robust isolation favors a hard boundary — a separate process, microVM, or container — over trusting an in-process language sandbox.
Because agents increasingly execute code — a tool that runs model-generated or user-supplied JavaScript or Python in a sandbox — and that sandbox becomes the trust boundary. 2026 saw repeated escapes in popular JavaScript sandboxes like vm2 and Enclave and in agent frameworks, where researchers showed an escape turns "the agent ran some code" into host RCE. It's the Excessive Agency problem from the OWASP LLM Top 10 made concrete: you can't trust the model's output, so the isolation around code execution has to hold — and software sandboxes keep failing. The right mitigation isn't a better in-process JS sandbox; it's a real isolation boundary — gVisor, a Firecracker microVM, or a disposable container with no network and least privilege — plus treating anything the agent can execute as untrusted and keeping the agent's capabilities minimal.
I'd focus on behavior rather than the specific bug, because the exploit lives inside a trusted process. The signatures: the Acrobat or Reader process — AcroRd32.exe or Acrobat.exe — doing things a PDF viewer shouldn't, like spawning a child process such as cmd or PowerShell, making outbound network connections to unfamiliar hosts right after a document opens, or reading sensitive files outside its normal scope. That maps to process-tree detection — a document handler spawning a shell or beaconing is the classic webshell-style signal — plus EDR telemetry on file reads and network connections attributed to the reader process. I'd also watch for the delivery: PDFs arriving via email or download with the Mark-of-the-Web, and at the network layer the data exfil and follow-on code retrieval the RSS.addFeed channel performs. And operationally, the fastest mitigation is patch velocity, since it was exploited for months — knowing where vulnerable Acrobat versions run is half the battle.
Sources
Public reporting and advisories used for this entry (verify against vendor advisories / NVD):
- The Hacker News — Adobe Reader zero-day exploited via malicious PDFs and Adobe patches CVE-2026-34621
- Help Net Security — Adobe emergency fix for CVE-2026-34621
- SecurityWeek — Adobe patches Reader zero-day exploited for months
- ThreatLocker — CVE-2026-34621 prototype pollution analysis
- Kodem — vm2 sandbox escapes turning AI agents into host RCE vectors