CVE-2026-21271

8.6

Adobe · Dreamweaver Desktop

Adobe Dreamweaver Desktop versions 21.6 and earlier contain an improper input validation vulnerability that could allow arbitrary code execution through malicious file interaction.

Executive summary

Adobe Dreamweaver Desktop versions 21.6 and earlier are vulnerable to arbitrary code execution, posing a significant risk to user systems if a malicious file is opened.

Vulnerability

The application fails to properly validate input, which can be exploited when a user is convinced to open a specially crafted malicious file. This vulnerability requires user interaction to execute, but it allows for code execution within the context of the current user.

Business impact

The potential for arbitrary code execution creates a high risk of total system compromise, including unauthorized data access and lateral movement within the network. With a CVSS score of 8.6, this vulnerability is categorized as High, reflecting the severe impact on confidentiality, integrity, and availability once the local user is compromised.

Remediation

Immediate Action: Update Adobe Dreamweaver Desktop to version 21.7 or later to implement the vendor provided security fix.

Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or unexpected file system modifications initiated by the Dreamweaver application.

Compensating Controls: Ensure that endpoint protection software is configured to scan all incoming files for malicious signatures before they are opened by users.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the high CVSS severity score, organizations should prioritize the deployment of version 21.7 across all workstations running Adobe Dreamweaver. Administrators must ensure that users are educated on the risks of opening untrusted files, as this remains the primary vector for triggering the vulnerability.

More Adobe CVEs

Sources