CVE-2026-27286: InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27286?
CVE-2026-27286 has a high severity rating due to its potential to disclose sensitive information.
How do I fix CVE-2026-27286?
To fix CVE-2026-27286, update Adobe InDesign Desktop to the latest version beyond 21.2.
What versions of InDesign Desktop are affected by CVE-2026-27286?
Adobe InDesign Desktop versions 20.5.2 and 21.2 and earlier are affected by CVE-2026-27286.
What type of vulnerability is CVE-2026-27286?
CVE-2026-27286 is a Heap-based Buffer Overflow vulnerability that could lead to memory exposure.
Can an attacker exploit CVE-2026-27286 remotely?
Yes, an attacker can exploit CVE-2026-27286 to disclose sensitive information remotely.