Heap-based Buffer Overflow in Adobe InDesign Desktop
CVE-2026-27286
5.5MEDIUM
What is CVE-2026-27286?
Adobe InDesign Desktop versions 20.5.2, 21.2, and earlier exhibit a heap-based buffer overflow vulnerability that could allow attackers to access sensitive information stored in memory. This vulnerability necessitates user action, as it requires the opening of a specially crafted malicious file to exploit. Organizations using these affected versions of Adobe InDesign should consider upgrading to mitigate potential security risks.
Affected Version(s)
InDesign Desktop 0 <= 21.2