Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Is CVE-2020-9715 exploited?
Listed in the CISA KEV catalog on 2026-04-13.
Federal remediation due 2026-04-27.
Past that date by 110 days.
EPSS puts exploitation in the next 30 days at 48%.
Public exploit code: none found in monitored sources.