Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
https://www.zerodayinitiative.com/advisories/ZDI-20-991/
https://www.securityweek.com/adobe-patches-55-vulnerabilities-across-11-products/
https://thehackernews.com/2026/04/cisa-adds-6-known-exploited-flaws-in.html
https://securityaffairs.com/190775/security/u-s-cisa-adds-adobe-fortinet-microsoft-windows-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://www.theregister.com/2026/04/13/ransomware_gang_other_crims_attacking/
https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9715
https://helpx.adobe.com/security/products/acrobat/apsb20-48.html
https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/
Source: Mitre, NVD
Published: 2020-08-19
Updated: 2026-04-14
Known Exploited Vulnerability (KEV)
Base Score: 9.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.7621