⚠ Actively exploited
Added to CISA KEV on 2026-04-13. Federal agencies required to patch by 2026-04-27. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2020-9715

CWE-416Use After Free10 documents8 sources
Severity
7.8HIGH
EPSS
50.4%
top 2.15%
CISA KEV
KEV
Added 2026-04-13
Due 2026-04-27
Exploit
No known exploits
Timeline
PublishedAug 19
KEV addedApr 13
KEV dueApr 27
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDadobe/acrobat_reader_dc15.006.3006015.006.30523+3
CVEListV5adobe/adobe_acrobat_and_reader2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier versions
NVDadobe/acrobat_dc15.006.3006015.006.30523+3

Patches

🔴Vulnerability Details

5
VulDB
Adobe Acrobat Reader use after free (APSB20-48)2026-04-13
GHSA
GHSA-wxg9-xx37-xj49: Adobe Acrobat and Reader versions 20202022-05-24
CVEList
CVE-2020-9715: Adobe Acrobat and Reader versions 20202020-08-19
VulnCheck
Adobe Acrobat Use-After-Free Vulnerability2020
Project0
Project Zero RCA: CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts

📋Vendor Advisories

1
CISA
Adobe Acrobat Use-After-Free Vulnerability2026-04-13

🕵️Threat Intelligence

3
Trendmicro
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader2020-09-03
Trendmicro
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader2020-09-03
Trendmicro
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader2020-09-03