High Known exploited (KEV) CVE-2009-3459

Heap Buffer Overflow in Adobe Acrobat/Reader (CVE-2009-3459) — Crafted PDF May Allow Remote Code Execution

Adobe Acrobat and Reader Added to KEV May 20, 2026 Federal remediation due 2026-06-03

A vulnerability in Adobe Acrobat and Reader (CVE-2009-3459) allows a crafted PDF to corrupt memory and potentially let a remote attacker run arbitrary code when the file is opened. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-05-20.

Key facts

  • CVE IDCVE-2009-3459
  • CVSS base score8.8 HIGH
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Adobe Acrobat and Reader
  • CWECWE-119
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-06-03 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Opening a crafted PDF can corrupt memory and may let a remote attacker execute arbitrary code (CVE-2009-3459).
  • Exploitation requires the user to open the file (UI:R in CVSS); routinely opened PDFs can be the entry point.
  • Official NVD CVSS is 8.8 (HIGH; CVSS:3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
  • CISA added it to the KEV catalog on 2026-05-20, with a remediation due date of 2026-06-03.
  • A 2009-era flaw entering KEV in 2026 shows that leaving old versions in place can still pose risk.

This vulnerability stems from how Adobe Acrobat and Reader handle memory when processing PDFs. A heap-based buffer overflow occurs when more data than a memory region is meant to hold gets written into it, corrupting internal data structures and creating room for attacker-supplied code to run. CISA's record states that a crafted PDF file induces memory corruption and may allow a remote attacker to execute arbitrary code. The attack requires the user to open the file (reflected as UI:R, meaning user interaction is needed, in the CVSS metrics), so everyday actions such as opening an email attachment or a downloaded document can serve as the entry point.

PDF is one of the most commonly opened document formats in both work and personal contexts, making this a textbook case of a document file itself becoming the attack vector. The official NVD CVSS score (a common standard for quantifying severity) is 8.8 (HIGH; CVSS:3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), a band reflecting high potential impact to confidentiality, integrity, and availability. Although this was originally disclosed back in 2009, its addition to the KEV catalog in May 2026 illustrates how continuing to run unsupported, outdated versions can still translate into real-world exposure.

The basic way to address this is to check the version of Acrobat/Reader in use and update to a supported release following Adobe's guidance. Under Binding Operational Directive (BOD) 22-01, CISA directs federal agencies to apply mitigations per vendor instructions, and to discontinue use of the product if mitigations cannot be applied. The remediation due date is set to 2026-06-03.

Why it matters

Because PDF is a standard business document format, this vulnerability has broad reach: many endpoints can be targeted through attachments and shared documents. Successful arbitrary code execution could lead to data exposure or tampering and operational disruption, and CISA's KEV listing (remediation due 2026-06-03) makes remediation mandatory for federal agencies. For organizations, the practical focus is inventorying Adobe Acrobat/Reader versions, updating to current releases, and setting rules for handling PDFs from unknown sources.

FAQ

How can I tell whether I am affected?
Start by checking the version of Adobe Acrobat/Reader you are running and updating to a supported release per Adobe's guidance. Under BOD 22-01, CISA directs applying mitigations per vendor instructions, or discontinuing use if mitigations cannot be applied.
Am I safe if I simply do not open PDFs?
This vulnerability assumes the user opens the file (UI:R in CVSS). Because PDFs are routinely opened via email and downloads, both careful handling of documents from unknown sources and keeping the software updated matter.
Why is a 2009 vulnerability getting attention in 2026?
Because CISA added it to the KEV catalog (a list of vulnerabilities with confirmed real-world exploitation) on 2026-05-20. It shows that even older flaws can become real threats where outdated, un-updated versions remain in use.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#CISA KEV#Adobe#Acrobat/Reader#PDF#buffer overflow#remote code execution#BOD 22-01
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.