Out-of-Bounds Write Vulnerability in Adobe InDesign Desktop
CVE-2026-27291
7.8HIGH
What is CVE-2026-27291?
Adobe InDesign Desktop versions 20.5.2, 21.2, and earlier are impacted by an out-of-bounds write vulnerability that could enable arbitrary code execution by an attacker. This exploitation necessitates user interaction; a victim must open a specifically crafted malicious file, which triggers the vulnerability and may allow unauthorized actions within the user’s session.
Affected Version(s)
InDesign Desktop 0 <= 21.2