OS Command Injection Vulnerability in Dreamweaver by Adobe
CVE-2026-21267

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 January 2026

What is CVE-2026-21267?

Adobe Dreamweaver Desktop versions 21.6 and earlier are susceptible to an OS Command Injection vulnerability. This vulnerability may allow an attacker to execute arbitrary code if a user opens a specially crafted malicious file. The exploitation process necessitates user interaction, wherein the victim must inadvertently trigger the vulnerability by accessing the compromised file. Immediate attention to updating and securing affected versions is crucial to mitigating this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Dreamweaver Desktop 0 <= 21.6

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.