CVE-2026-34700: InDesign Desktop | Out-of-bounds Write (CWE-787)
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not open InDesign files from untrusted or unexpected sources. Instruct users to verify senders and avoid opening suspicious .indd or other InDesign files; if a file must be inspected, open it only in an isolated/sandboxed environment (virtual machine) until a vendor patch is available.
- Compensating control
Block, quarantine, or scan InDesign file attachments at email gateways, web upload points, and perimeter security controls. Configure malware scanning and manual review for inbound files that could contain malicious InDesign documents to reduce the chance a user will open a crafted malicious file.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34700?
CVE-2026-34700 has a severity rating of 7.8, classified as high.
How do I fix CVE-2026-34700?
To fix CVE-2026-34700, users should update to the latest version of Adobe InDesign Desktop.
What does CVE-2026-34700 affect?
CVE-2026-34700 affects Adobe InDesign Desktop versions 21.3, 20.5.3, and earlier.
What could happen if CVE-2026-34700 is exploited?
Exploitation of CVE-2026-34700 could lead to arbitrary code execution in the context of the current user.
Is user interaction required to exploit CVE-2026-34700?
Yes, exploitation of CVE-2026-34700 requires user interaction, specifically opening a malicious file.