CVE-2026-21357: InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21357?
CVE-2026-21357 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-21357?
To mitigate CVE-2026-21357, update Adobe InDesign Desktop to version 21.2 or later.
What types of systems are affected by CVE-2026-21357?
CVE-2026-21357 affects Adobe InDesign Desktop versions 21.1, 20.5.1, and earlier, on both Windows and macOS systems.
What is a Heap-based Buffer Overflow in the context of CVE-2026-21357?
A Heap-based Buffer Overflow like that in CVE-2026-21357 allows attackers to exploit memory management errors to execute arbitrary code.
What do I need to do to be safe from CVE-2026-21357?
To remain safe from CVE-2026-21357, ensure that your version of Adobe InDesign is updated and avoid opening untrusted files.