← Vulnerability feed

Vulnerability record · CVE-2020-9715 · published 19 August 2020

CVE-2020-9715: Adobe Acrobat and Reader use-after-free allows code execution

Adobe · Acrobat Dc

Adobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier. Successful exploitation can lead to arbitrary code execution in the context of the affected application. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed target in real-world attacks.

7.8 CVSS 3.1 High CISA KEV since 13 Apr 2026 EPSS 49% · top 1.2% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 9.3
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityConfirmed exploitation via CISA KEV plus very high EPSS probability, with arbitrary code execution impact, though it requires local user interaction to trigger.

What it is

Adobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier. Successful exploitation can lead to arbitrary code execution in the context of the affected application. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed target in real-world attacks.

Impact

An attacker who gets a crafted file opened can execute arbitrary code on the victim's machine, giving full control of the user's session and data. Because the vector is local with user interaction, the practical gain is code execution on the endpoint rather than remote server compromise.

Attack surface

Reached by convincing a user to open a malicious PDF or related file in Acrobat or Reader; the CVSS vector is AV:L/AC:L/PR:N/UI:R, so no privileges are needed but user interaction is required. No network-facing service is involved.

Exploitation

CVE-2020-9715 is in CISA's KEV catalog (added 2026-04-13, due 2026-04-27) and EPSS shows a 30-day probability of 0.48595 (98.8th percentile), indicating high likelihood of exploitation. Reference tags include Exploit, and no ransomware campaign use is documented.

What to do

  • Apply the vendor patch per Adobe security bulletin APSB20-48 and upgrade Acrobat and Reader to a fixed release.
  • If patching cannot be done immediately, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
  • Restrict or block untrusted PDF attachments at email and web gateways, and disable automatic opening of PDFs from untrusted sources.
  • Run Acrobat and Reader with reduced privileges and enable Protected View/Protected Mode where available.
  • Track KEV remediation deadlines (due 2026-04-27) and confirm all endpoints are updated.

Detection

  • Monitor for Acrobat/Reader processes spawning child processes such as cmd.exe, powershell.exe, or scripting hosts, which is abnormal for normal PDF viewing.
  • Alert on crashes or abnormal termination of Acrobat/Reader followed by suspicious process creation, consistent with use-after-free exploitation.
  • Hunt for PDF files delivered via email or web downloads that are opened shortly before unusual child-process activity on the same host.
  • Inventory Acrobat and Reader versions across endpoints and flag any still matching the affected version ranges.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-9715 to the Known Exploited Vulnerabilities catalog on 13 April 2026 as "Adobe Acrobat Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 April 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2018-4990Adobe Acrobat and Reader double free allows code executionAdobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and e…KEVEPSS 36%analysed8.6CVE-2026-34621Adobe Acrobat Reader prototype pollution leads to code executionAdobe Acrobat and Reader (versions 24.001.30356, 26.001.21367 and earlier) are affected by prototype pollution (CWE-1321) that can result in arbitrar…KEVEPSS 2.2%analysed7.8CVE-2023-26369Adobe Acrobat and Reader out-of-bounds write allows code executionAdobe Acrobat and Reader versions 23.003.20284, 20.005.30516 and 20.005.30514 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to…KEVEPSS 6.7%analysed7.8CVE-2023-21608Adobe Acrobat Reader use-after-free allows arbitrary code executionAdobe Acrobat and Reader are affected by a use-after-free (CWE-416) that can lead to arbitrary code execution in the context of the current user. The…KEVEPSS 61%analysed10.0CVE-2018-4872Adobe acrobat vulnerabilityAn issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …EPSS 12%10.0CVE-2016-1044Adobe acrobat improper access control vulnerabilityAdobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…EPSS 6.9%

Source: NIST National Vulnerability Database (record CVE-2020-9715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.