CVE-2026-21267
8.6Adobe · Dreamweaver Desktop
Adobe Dreamweaver Desktop versions 21.6 and earlier are vulnerable to OS Command Injection, which may allow an attacker to execute arbitrary code if a user opens a malicious file.
Executive summary
Adobe Dreamweaver Desktop versions 21.6 and earlier are susceptible to an OS Command Injection vulnerability that could lead to arbitrary code execution upon opening a malicious file.
Vulnerability
This vulnerability is classified as an OS Command Injection (CWE-78) flaw. It requires user interaction, specifically the opening of a malicious file by a victim, to trigger the execution of arbitrary commands.
Business impact
The potential for arbitrary code execution poses a severe threat to system integrity and data confidentiality. Given the CVSS score of 8.6, this vulnerability represents a high risk to organizational security, as successful exploitation could allow an attacker to gain full control over the affected workstation or environment.
Remediation
Immediate Action: Update Adobe Dreamweaver Desktop to version 21.7 or later to implement the vendor-supplied fix.
Proactive Monitoring: Monitor endpoint activity for unusual process spawns or unexpected command-line arguments originating from the Dreamweaver application.
Compensating Controls: Implement endpoint protection policies that restrict the execution of unauthorized binaries and utilize email or file-scanning tools to inspect incoming files for malicious content before they are opened by users.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
This vulnerability presents a high risk due to the potential for full system compromise via arbitrary code execution. Administrators should prioritize updating all instances of Adobe Dreamweaver Desktop to version 21.7 immediately to eliminate the underlying flaw. User awareness training regarding the risks of opening untrusted files is also strongly recommended as a defense-in-depth measure.