CVE-2020-9715Active Exploitation(adobe / acrobat_dc)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch adobe acrobat_dc systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat_dc
  • acrobat_reader_dc
  • macos
  • windows

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days

What's happening

  • Active exploitation reported across 7 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-04-13); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Products
acrobat_dcacrobat_reader_dcmacoswindows

2 versions affected across 4 products

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-04-13: 5Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-14: 1Active Exploitation · 2026-04-13: 3Active Exploitation · 2026-04-14: 2Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-13: 2Patch / Workaround · 2026-04-14: 2Technical Details · 2026-04-13: 4Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 104-1304-1404-1504-16
Signal classification3 categories
Active Exploitation
666.7%
Patch
222.2%
Disclosure
111.1%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-04-135
Active Exploitation2Disclosure1Patch2
2026-04-142
Active Exploitation2
2026-04-151
Active Exploitation1
2026-04-161
Active Exploitation1
Full discourse9 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    6 ثغرات تهدد اغلب الاجهزة والشبكات يتم استغلالها حاليا 🚨 CISA أضافت 6 ثغرات جديدة لقائمة (KEV)Known Exploited Vulnerabilities بعد تأكد الاستغلال الفعلي لها حاليا من قبل المخترقين. الثغرة CVE-2026-21643 (CVSS: 9.1) 🔴 المنتج: FortiClient EMS من Fortinet النوع: SQL Injection التأثير: تنفيذ كود خبيث بدون مصادقة الحالة: استغلال مؤكد منذ 24 مارس 2026 الثغرة CVE-2020-9715 (CVSS: 7.8)🟠 المنتج: Adobe Acrobat Reader النوع: Use-After-Free التأثير: Remote Code Execution ثغرة تستغل من (2020) ولكن تم اكتشافها والاعلان عنها مؤخرا الثغرة CVE-2023-36424 (CVSS: 7.8) 🟠 المنتج: Microsoft Windows Common Log File System Driver النوع: Out-of-Bounds Read التأثير: Privilege Escalation ما فيه تقارير استغلال علنية، بس CISA تؤكد انها تتسغل حاليا . الثغرة CVE-2023-21529 (CVSS: 8.8) 🔴 المنتج: Microsoft Exchange Server النوع: Deserialization of Untrusted Data التأثير: Remote Code Execution المجموعة الصينية Storm-1175 تستغلها لـ Medusa Ransomware. الثغرة CVE-2025-60710 (CVSS: 7.8)🟠 المنتج: Host Process for Windows Tasks النوع: Improper Link Resolution Before File Access التأثير: Local Privilege Escalation الثغرة CVE-2012-1854 (CVSS: 7.8) 📅🟠 المنتج: Microsoft Visual Basic for Applications (VBA) النوع: Insecure Library Loading التأثير: Remote Code Execution ثغرة من 2012! Microsoft عمرها ١٤ سنه ولاتزال تستغل

    Post summary

    The post lists six CVEs that CISA confirms are actively exploited in the wild, providing detailed technical data but offering no PoC, patch, or mitigation information.

    16020152.6K
    49.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/13追加) 🛡️No.1561 CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / CISA-ADP ・種別:信頼できない検索パス (CWE-426) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Visual Basic for Applications (VBA) において、DLL検索パスの処理に不備が存在。事前認証されていない攻撃者により、細工されたDLLを特定ディレクトリに配置されることで、正規ライブラリにかわって読み込まされる恐れがある。結果、ユーザーが対象ファイルを開くことで、任意コードが実行される可能性がある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・攻撃者がDLLを配置できる環境であること ・ユーザーが細工されたファイルを開くこと ・VBAが有効な環境 ________________________________________ ✅悪用時影響 ・任意コード実行(ユーザー権限) ・情報漏えいおよび改ざん ・システム可用性への影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2012-1854 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046   🛡️No.1562 CVE-2025-60710 Microsoft Windows Link Following Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Windows において、リンク解決処理に不備が存在。認証済みの攻撃者により、細工されたリンクを介して、本来アクセスできないリソースへアクセスされ、ローカル環境で権限昇格される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ローカルアクセスが可能であること ・低権限ユーザーであること ・ユーザー操作不要 ________________________________________ ✅悪用時影響 ・権限昇格 ・機密情報の取得および改ざん ・システムへの影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-60710 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710   🛡️No.1563 CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability ✅概要 ・深刻度:8.8 High (CVSS Base) / NVD ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Exchange Serverにおいて、信頼できないデータのデシリアライズ処理に起因する脆弱性が存在。認証済みの攻撃者により、細工されたデータをサーバー上で処理されることで、コード実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・認証済みユーザ権限が必要 ・Exchange Serverへのネットワークアクセス ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報漏えい、改ざん、サービス影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-21529 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529   🛡️No.1564 CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:境界外読み取り (CWE-125) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Microsoft Windowsにおいて、境界外読み取りに起因する脆弱性が存在。認証済みの攻撃者により、不正なメモリアクセスを引き起こされることで、機密情報を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ________________________________________ ✅攻撃前提条件 ・ローカルでのログオン権限が必要 ________________________________________ ✅悪用時影響 ・機密情報の漏えい ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-36424 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424   🛡️No.1565 CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:解放後使用 (CWE-416) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、解放後使用に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたPDFファイルをユーザーに開かせることで、メモリ破損を引き起こし、任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ユーザが細工されたPDFファイルを開く必要がある ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2020-9715 https://helpx.adobe.com/security/products/acrobat/apsb20-48.html   🛡️No.1566 CVE-2026-21643 Fortinet FortiClientEMS SQL Injection Vulnerability ✅概要 ・深刻度:9.8 Critical (CVSS Base) / NVD ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiClientEMSにおいて、SQLコマンドで使用される特殊要素の不適切な無効化に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたHTTPリクエストを送信されることで、SQLインジェクションを引き起こされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・対象システムへネットワークアクセス可能 ________________________________________ ✅悪用時影響 ・任意コマンド実行 ・機密情報の漏えい、改ざん、サービス停止 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:あり(セキュリティ企業による報告) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-21643 https://www.fortiguard.com/psirt/FG-IR-26-XXX   🛡️No.1567 CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability ✅概要 ・深刻度:8.6 High (CVSS Base) / Adobe Systems Incorporated ・種別:オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染) (CWE-1321) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、オブジェクトプロトタイプ属性の不適切に制御された変更に起因する脆弱性が存在。ユーザー権限で任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・被害者が悪意のあるファイルを開く必要がある ・対象端末でAdobe AcrobatまたはReaderが利用されている必要がある ________________________________________ ✅悪用時影響 ・現在のユーザー権限で任意コード実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:Adobeが悪用を確認 (Adobeヘルプセンター) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-34621 https://helpx.adobe.com/security/products/acrobat/apsb26-43.html https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA catalogued seven vulnerabilities that have been confirmed to be actively exploited, providing detailed technical info, impact assessments, and vendor mitigation links, with a public PoC noted for one case.

    000635.7K
    43.5K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA added 7 CVEs to the KEV catalog today. All confirmed active exploitation. CVE-2012-1854 — Microsoft VBA insecure library loading CVE-2020-9715 — Adobe Acrobat UAF CVE-2023-21529 — Exchange deserialization CVE-2023-36424 — Windows OOB read CVE-2025-60710 — Windows link following CVE-2026-21643 — Fortinet SQL injection CVE-2026-34621 — Adobe Acrobat prototype pollution A CVE from 2012 is still being actively exploited in 2026. Patch prioritization isn’t optional. Source: https://t.me/VulnerabilityNews/41878 → http://cisa.gov/known-exploited-vulnerabilities-catalog

    Post summary

    CISA announces seven CVEs with confirmed active exploitation, urging urgent patching of vulnerabilities ranging from Adobe Acrobat UAF to Fortinet SQL injection.

    11030214
    184 followersView on X
  • キタきつね@foxbook
    Disclosure

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (Apr 13) CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adobe AcrobatのUse-After-Free脆弱性 CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性 CVE-2026-34621 Adobe AcrobatおよびReaderプロトタイプ汚染の脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced the addition of seven known exploited CVEs to its catalog, listing each CVE with a short technical description but providing no PoC, exploit code, patch, or debunking information.

    00030341
    4.9K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adob​​e AcrobatのUse-After-Free脆弱性

    Post summary

    CISA has added seven known exploited vulnerabilities, including CVE-2012-1854 and CVE-2020-9715, to its catalog, indicating they are actively exploited in the wild.

    1000056
    40 followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2020-9715 #Adobe #Acrobat Use-After-Free Vulnerability https://www.scyscan.com/cve-2020-9715/adobe-acrobat-use-after-free-vulnerability/

    Post summary

    The post lists CVE-2020-9715 as a known exploited vulnerability in Adobe Acrobat, confirming its use‑after‑free flaw is actively abused, though no exploit code or patch details are provided.

    0000035
    61 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Patch

    🛡️ CVE-2020-9715: Vulnerabilidad Use-After-Free en Adobe Acrobat Explotada Análisis técnico de CVE-2020-9715, una vulnerabilidad de use-after-free en Adobe Acrobat que permite ejecución de código. Impacto, mitigaciones y recomendacione https://www.ciberplaneta.org/vulnerabilidades/cve-2020-9715-vulnerabilidad-use-after-free-en-adobe-acrobat-explotada/ #ciberplaneta #vulnerabilidades #cve_2020_9715 #cve #vulnerabilidad #adobe #seguridad #infosec #ciberseguridad

    Post summary

    The post offers a technical breakdown of CVE‑2020‑9715, a use‑after‑free flaw in Adobe Acrobat that enables code execution, and outlines mitigations and recommendations.

    0000027
    5 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Patch

    🛡️ Alerta de Seguridad: Vulnerabilidad Use-After-Free en Adobe Acrobat (CVE-2020-9715) Adobe Acrobat presenta una vulnerabilidad de uso después de liberación (use-after-free) que permite ejecución de código arbitrario. Afecta a versiones previas al parche de noviembre 2020. Severidad CVSS 7.8 (Alta). Recomendación: aplicar actualizaciones inmediatas per APSB20-48. https://www.ciberplaneta.org/boletines/83/ #ciberplaneta #bulletin #cybersecurity #cve #adobe #acrobat #ioc #infosec #ciberseguridad

    Post summary

    CVE‑2020‑9715 is a use‑after‑free flaw in Adobe Acrobat that allows arbitrary code execution; patches are available (APSB20‑48) and should be applied immediately.

    0000027
    5 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🚨 BREAKING: CISA updates its Known Exploited Vulnerabilities Catalog with seven new entries, including CVE-2012-1854 and CVE-2020-9715. These vulnerabilities are actively exploited, urging immediate attention from IT teams. #CyberSecurity #BreakingNews https://t.co/m8vrB0xob7

    Post summary

    CISA has added seven new CVEs to its catalog of known exploited vulnerabilities and explicitly states they are actively exploited, urging IT teams to take immediate action.

    0000028
    55 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat_dc---
Appadobeacrobat_dc---
Appadobeacrobat_dc20.001.30002--
Appadobeacrobat_reader_dc---
Appadobeacrobat_reader_dc---
Appadobeacrobat_reader_dc20.001.30002--
OSapplemacos---
OSmicrosoftwindows---

Explore more