Heap-based Buffer Overflow in Adobe InCopy Affects User Security
CVE-2026-21281

7.8HIGH

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
13 January 2026

What is CVE-2026-21281?

A heap-based buffer overflow vulnerability in Adobe InCopy versions 21.0 and 19.5.5 and earlier could allow an attacker to execute arbitrary code within the context of an affected user. The successful exploitation of this vulnerability necessitates user interaction, as the affected user must open a specially crafted malicious file. Proper user education and application updates are crucial to mitigate this threat.

Affected Version(s)

InCopy 0 <= 19.5.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.