CVE-2026-27287: InCopy | Out-of-bounds Read (CWE-125)
InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27287?
CVE-2026-27287 is classified as a moderate severity vulnerability due to the potential for code execution.
How do I fix CVE-2026-27287?
To fix CVE-2026-27287, update Adobe InCopy to the latest version beyond 21.2.
Who is affected by CVE-2026-27287?
CVE-2026-27287 affects users of Adobe InCopy versions 20.5.2 through 21.2.
What type of vulnerability is CVE-2026-27287?
CVE-2026-27287 is an out-of-bounds read vulnerability, identified as CWE-125.
Can CVE-2026-27287 be exploited remotely?
Yes, CVE-2026-27287 can potentially be exploited remotely by opening a crafted file.