CVE-2026-27280: DNG SDK | Out-of-bounds Write (CWE-787)
Published Mar 10, 2026
·Updated
DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
DNG DNG SDK<1.7.1 2471
Adobe DNG Software Development Kit<=1.7.1
Event History
Mar 10, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-27280?
CVE-2026-27280 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-27280?
To mitigate CVE-2026-27280, update the DNG SDK to version 1.7.1 2472 or later.
3
Who is affected by CVE-2026-27280?
CVE-2026-27280 affects users of DNG SDK versions 1.7.1 2471 and earlier.
4
What can happen if CVE-2026-27280 is exploited?
Exploitation of CVE-2026-27280 can lead to arbitrary code execution in the context of the current user.
5
Does CVE-2026-27280 require user interaction for exploitation?
Yes, exploitation of CVE-2026-27280 requires the victim to open a malicious file.