CVE-2026-27283: InDesign Desktop | Use After Free (CWE-416)
Published Apr 14, 2026
·Updated
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
5 affected components
Adobe InDesign Desktop<=20.5.2, <=21.2
All of the following
Any of the following
Adobe InDesign<20.5.3
Adobe InDesign>=21.0<21.3
Any of the following
Apple macOS
Microsoft Windows
Event History
Apr 14, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-27283?
CVE-2026-27283 is considered to have a critical severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2026-27283?
To address CVE-2026-27283, users should update Adobe InDesign Desktop to the latest version beyond 21.2.
3
What versions of InDesign Desktop are affected by CVE-2026-27283?
CVE-2026-27283 affects Adobe InDesign Desktop versions 20.5.2, 21.2, and earlier.
4
What type of vulnerability is CVE-2026-27283?
CVE-2026-27283 is a Use After Free vulnerability classified under CWE-416.
5
Does exploitation of CVE-2026-27283 require user interaction?
Yes, exploitation of CVE-2026-27283 requires user interaction to be successful.