CVE-2026-21353: DNG SDK | Integer Overflow or Wraparound (CWE-190)
Published Feb 10, 2026
·Updated
DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
DNG DNG SDK<1.7.1 2410
Adobe DNG Software Development Kit<1.7.2
Event History
Feb 10, 2026
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21353?
CVE-2026-21353 has a high severity as it could allow arbitrary code execution.
2
How do I fix CVE-2026-21353?
To fix CVE-2026-21353, update the DNG SDK to a version later than 1.7.1 2410.
3
What causes CVE-2026-21353?
CVE-2026-21353 is caused by an integer overflow or wraparound vulnerability in the DNG SDK.
4
Who is affected by CVE-2026-21353?
Users of DNG SDK versions 1.7.1 2410 and earlier are affected by CVE-2026-21353.
5
What are the implications of exploiting CVE-2026-21353?
Exploiting CVE-2026-21353 could allow an attacker to execute arbitrary code in the context of the current user.