๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Summary
Adobe Acrobat and Reader have a heap-based buffer overflow vulnerability (a memory safety flaw where data overflows into adjacent memory, potentially allowing attackers to run malicious code) that can be triggered by opening a specially crafted PDF file. This vulnerability is actively being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Details
EPSS: 87.0%
Yes
๐ฅ Actively Exploited
May 19, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2009-3459
First tracked: May 20, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%