CVE-2026-21281: InCopy | Heap-based Buffer Overflow (CWE-122)
InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21281?
CVE-2026-21281 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-21281?
To fix CVE-2026-21281, users should update to the latest version of Adobe InCopy that addresses the heap-based buffer overflow vulnerability.
What versions of Adobe InCopy are affected by CVE-2026-21281?
CVE-2026-21281 affects Adobe InCopy versions 21.0, 19.5.5, and earlier.
What type of vulnerability is CVE-2026-21281?
CVE-2026-21281 is a heap-based buffer overflow vulnerability.
What are the risks associated with CVE-2026-21281?
Exploitation of CVE-2026-21281 could lead to arbitrary code execution in the context of the current user, posing a significant security risk.