CyberMax
Home › Exploited CVEs › Adobe

Adobe Acrobat and Reader known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 13 Adobe Acrobat and Reader CVEs as exploited in the wild. 2 were added in the last 12 months and 1 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 13 Adobe Acrobat and Reader CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2008-2992Reader and Acrobat Input Validation98.5%Yes2022-03-032022-03-24
2CVE-2007-5659Acrobat and Reader Buffer Overflow87.4%–2022-06-082022-06-22
3CVE-2009-3459Acrobat and Reader Heap-Based Buffer Overflow86.6%–2026-05-202026-06-03
4CVE-2021-21017Acrobat and Reader Heap-based Buffer Overflow86.3%–2021-11-032021-11-17
5CVE-2009-3953Acrobat and Reader Universal 3D Remote Code Execution83.2%–2022-06-082022-06-22
6CVE-2009-4324Acrobat and Reader Use-After-Free81.9%–2022-06-082022-06-22
7CVE-2010-2883Acrobat and Reader Stack-Based Buffer Overflow81.4%–2022-06-082022-06-22
8CVE-2023-21608Acrobat and Reader Use-After-Free61.5%–2023-10-102023-10-31
9CVE-2021-28550Acrobat and Reader Use-After-Free52.0%–2021-11-032021-11-17
10CVE-2008-0655Acrobat and Reader Unspecified37.9%–2022-06-082022-06-22
11CVE-2018-4990Acrobat and Reader Double Free36.2%–2022-06-082022-06-22
12CVE-2023-26369Acrobat and Reader Out-of-Bounds Write6.7%–2023-09-142023-10-05
13CVE-2026-34621Acrobat and Reader Prototype Pollution2.2%–2026-04-132026-04-27
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Adobe KEV CVEs · other Adobe products: ColdFusion · Flash Player · Reader and Acrobat · free KEV badge for Adobe · all vendors