LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-9715: Adobe Acrobat Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-9715 to its Known Exploited Vulnerabilities catalog on Apr 13, 2026, with a federal patch deadline of Apr 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

Adobe Acrobat contains a use-after-free vulnerability that can allow an attacker to execute arbitrary code on an affected system. This matters for IT and security teams because Acrobat is widely deployed for document handling, and successful exploitation can lead to full compromise of the workstation without user interaction beyond opening a crafted file.

How it works

The weakness is classified as CWE-416, a use-after-free condition. In this class of flaw, a program continues to reference memory after it has been freed, allowing an attacker to manipulate that memory region. An attacker can abuse the condition to influence program control flow and achieve code execution.

Technical readers should treat any use-after-free in a document parser as a potential remote code execution path. Exact trigger conditions and memory layout requirements are not provided here and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Adobe Acrobat runs on Windows and macOS endpoints, often as part of standard productivity deployments. Inventory all installations of Adobe Acrobat and Reader through endpoint management tools, software inventory agents, or file-system scans for acrobat.exe and related binaries.

Specific affected versions and configuration details are not supplied in the summary and must be confirmed against the vendor advisory.

How to remediate

Apply the vendor-supplied update as the primary remediation step. The CISA required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the update can be applied, implement compensating controls to reduce exposure. Segment endpoints that handle untrusted PDFs so they have limited network access and cannot easily reach sensitive internal systems.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches involving credential theft and lateral movement. Organizations can run a free exposure scan of their email domains against known breach data to determine whether related account information has already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat
WeaknessCWE-416
Added to CISA KEVApr 13, 2026
Federal patch deadlineApr 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities