Skip to content
COOEY

EXPOSURES › CVE-2020-9715

CVE-2020-9715

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9715 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild.

This use-after-free flaw in Adobe Acrobat allows attackers to execute arbitrary code remotely, posing a severe risk to DIB organizations relying on Acrobat for document handling. The vulnerability was actively exploited before a patch existed, creating a zero-day window that compromises confidentiality and integrity of sensitive data. DIB orgs must immediately patch Acrobat and audit all document processing workflows to prevent unauthorized access.

Shame score — Adobe failed to patch a critical use-after-free vulnerability promptly, allowing active exploitation in the wild before disclosure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized