LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-3459 to its Known Exploited Vulnerabilities catalog on May 20, 2026, with a federal patch deadline of Jun 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

This vulnerability is a heap-based buffer overflow in Adobe Acrobat and Reader. It allows remote attackers to execute arbitrary code when a user opens a crafted PDF file that triggers memory corruption. The issue affects systems that process untrusted PDF documents with these applications.

How it works

The weakness falls under CWE-119, a buffer overflow condition. An attacker supplies a PDF that causes the application to write beyond allocated heap memory during parsing or rendering.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader are installed on endpoint workstations and servers for viewing or editing PDF files. Inventory all systems for these applications using standard software discovery tools or configuration management databases.

How to remediate

Apply the vendor update referenced in the official advisory as the primary step. After patching, review default PDF handling settings and restrict automatic execution of embedded content where possible.

If you can't patch immediately

Apply mitigations according to the vendor instructions and any applicable CISA guidance such as BOD 22-01 for cloud services. Segment networks so that endpoints handling PDFs are isolated from critical assets.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to system compromise and subsequent data exposure. Run a free exposure scan of your email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader
WeaknessCWE-119
Added to CISA KEVMay 20, 2026
Federal patch deadlineJun 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities