Adobe Acrobat and Reader known exploited vulnerabilities, ranked
CISA lists 13 Adobe Acrobat and Reader CVEs as exploited in the wild. 2 were added in the last 12 months and 1 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2008-2992: EPSS 98.5%, used in ransomware, added 2022-03-03
- CVE-2007-5659: EPSS 87.4%, added 2022-06-08
- CVE-2009-3459: EPSS 86.6%, added 2026-05-20
- CVE-2021-21017: EPSS 86.3%, added 2021-11-03
- CVE-2009-3953: EPSS 83.2%, added 2022-06-08
All 13 Adobe Acrobat and Reader CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2008-2992 | Reader and Acrobat Input Validation | 98.5% | Yes | 2022-03-03 | 2022-03-24 |
| 2 | CVE-2007-5659 | Acrobat and Reader Buffer Overflow | 87.4% | – | 2022-06-08 | 2022-06-22 |
| 3 | CVE-2009-3459 | Acrobat and Reader Heap-Based Buffer Overflow | 86.6% | – | 2026-05-20 | 2026-06-03 |
| 4 | CVE-2021-21017 | Acrobat and Reader Heap-based Buffer Overflow | 86.3% | – | 2021-11-03 | 2021-11-17 |
| 5 | CVE-2009-3953 | Acrobat and Reader Universal 3D Remote Code Execution | 83.2% | – | 2022-06-08 | 2022-06-22 |
| 6 | CVE-2009-4324 | Acrobat and Reader Use-After-Free | 81.9% | – | 2022-06-08 | 2022-06-22 |
| 7 | CVE-2010-2883 | Acrobat and Reader Stack-Based Buffer Overflow | 81.4% | – | 2022-06-08 | 2022-06-22 |
| 8 | CVE-2023-21608 | Acrobat and Reader Use-After-Free | 61.5% | – | 2023-10-10 | 2023-10-31 |
| 9 | CVE-2021-28550 | Acrobat and Reader Use-After-Free | 52.0% | – | 2021-11-03 | 2021-11-17 |
| 10 | CVE-2008-0655 | Acrobat and Reader Unspecified | 37.9% | – | 2022-06-08 | 2022-06-22 |
| 11 | CVE-2018-4990 | Acrobat and Reader Double Free | 36.2% | – | 2022-06-08 | 2022-06-22 |
| 12 | CVE-2023-26369 | Acrobat and Reader Out-of-Bounds Write | 6.7% | – | 2023-09-14 | 2023-10-05 |
| 13 | CVE-2026-34621 | Acrobat and Reader Prototype Pollution | 2.2% | – | 2026-04-13 | 2026-04-27 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Adobe KEV CVEs · other Adobe products: ColdFusion · Flash Player · Reader and Acrobat · free KEV badge for Adobe · all vendors