Safeguard
Vulnerability Analysis

Three Adobe Acrobat and Reader Bugs, From a 2009 Overflow to This Year's Prototype Pollution

A heap overflow first exploited in 2009, a use-after-free from 2020, and a fresh prototype pollution bug — all three confirmed exploited against Adobe Acrobat and Reader within weeks of each other.

Safeguard Research Team
4 min read

Three separate Adobe Acrobat and Reader vulnerabilities, spanning a heap-based buffer overflow first exploited in 2009, a use-after-free confirmed in 2020, and a prototype pollution bug confirmed just this year, were all added to CISA's Known Exploited Vulnerabilities catalogue within a few weeks of each other in April and May of this year.

CVECVSSBug classAdded to KEV
CVE-2009-34598.8Heap-based buffer overflow20 May 2026
CVE-2026-346218.6Prototype pollution13 Apr 2026
CVE-2020-97157.8Use-after-free13 Apr 2026

Why the same two products keep producing the same outcome

All three of these vulnerabilities land in the exact same place: a crafted document, opened by a user, triggers memory corruption or object-model manipulation inside Acrobat or Reader that ultimately hands an attacker code execution in the context of the person who opened the file. CVE-2009-3459 is a heap-based buffer overflow triggered by a malformed PDF. CVE-2020-9715 is a use-after-free with the same end effect. CVE-2026-34621, the newest of the three, is a prototype pollution vulnerability — a bug class more commonly associated with JavaScript engines than PDF readers, which is itself a reminder of how much scripting and object-model complexity now lives inside a "document viewer." All three require the victim to open a file, which places social engineering, not network exploitation, as the actual first step in every one of these attack chains.

The seventeen-year gap between CVE-2009-3459's original disclosure and its confirmed exploitation in the wild this year is the most striking detail in this cluster. A bug patched in Acrobat and Reader versions that predate the current release by well over a decade is still capable of being weaponized against a system today, which only happens when an organization is running software so far out of support that a sixteen-year-old patch was never applied, or when an attacker successfully repackages an old technique against a target still exposed through some other path — a cracked or pirated install, an air-gapped workstation frozen at an old build, or a device that fell out of the patch cycle entirely.

What to check this week

Confirm Acrobat and Reader are on current, vendor-supported release branches across every endpoint, not just the ones IT actively provisions — old installers from years-old software deployment images are a common source of exactly this kind of exposure.

Treat PDF attachments from external senders as an active threat vector, particularly in phishing-prone departments like finance and HR, given that all three vulnerabilities in this cluster require nothing more than a user opening a file.

Prioritize CVE-2026-34621 and CVE-2009-3459 given their higher CVSS scores, both landing at the top of the severity range for this cluster and both enabling arbitrary code execution.

Audit for legacy or unmanaged Acrobat/Reader installs specifically — CVE-2009-3459's confirmed exploitation this year is a strong signal that outdated installations of exactly this kind still exist in production environments somewhere.

Why "just a PDF reader" undersells the actual attack surface

Acrobat and Reader are treated by most security teams as a commodity utility rather than a piece of software worth independent scrutiny, largely because the product's purpose — viewing documents — feels passive. But the underlying codebase has to parse an enormously complex file format, execute embedded JavaScript, render forms, and increasingly support object-model behaviors sophisticated enough to be vulnerable to prototype pollution, a bug class born in web browsers. Every one of those capabilities is attack surface, and this cluster's three CVEs, spanning heap overflows, use-after-free, and prototype pollution, demonstrate that the product's vulnerability history covers nearly the full range of modern memory-safety and object-model bug classes, not just one narrow category.

A closing note on patch cadence versus attacker patience

The confirmed exploitation of a sixteen-year-old Adobe vulnerability this year says something uncomfortable about attacker economics: old, well-understood bugs against widely deployed software remain profitable to weaponize for as long as any meaningful population of unpatched installs exists, regardless of how long ago the vendor shipped a fix. Patch cadence discipline has to account for that reality rather than assuming a bug's age is itself a mitigating factor.

How Safeguard helps

Safeguard's continuous inventory flags outdated Acrobat and Reader installations across an organization's full endpoint fleet, including the unmanaged or long-forgotten deployments that a point-in-time patch review is most likely to miss — exactly the kind of gap that let a sixteen-year-old vulnerability get confirmed exploited again this year.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.