CVE-2026-21352

7.8

Adobe · Adobe DNG Software Development Kit (SDK)

Adobe DNG SDK versions 1.7.1.2410 and earlier are vulnerable to an out-of-bounds write, potentially allowing arbitrary code execution through the opening of a malicious file.

Executive summary

Adobe DNG SDK contains an out-of-bounds write vulnerability that could lead to arbitrary code execution if a user opens a specially crafted file.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) triggered when the software parses a malicious file. Successful exploitation requires user interaction and can occur in the context of the current user.

Business impact

Successful exploitation allows an attacker to execute arbitrary code on the victim's system, potentially leading to full system compromise or data theft. Given the CVSS score of 7.8, this flaw represents a high-severity risk to operational security, as it effectively leverages user interaction to bypass perimeter defenses and gain local execution privileges.

Remediation

Immediate Action: Update all implementations of the Adobe DNG SDK to version 1.7.1.2471 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system logs for unusual application crashes or process execution patterns associated with DNG file processing.

Compensating Controls: Ensure that users are instructed to avoid opening untrusted or unexpected DNG files from unknown sources, and maintain robust endpoint protection software to detect suspicious file-based activity.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability poses a significant risk to any environment processing untrusted DNG files. IT administrators and developers should prioritize patching their SDK implementations to the fixed version immediately. Failure to remediate this flaw leaves endpoints susceptible to arbitrary code execution, which could result in unauthorized access to sensitive data or further lateral movement within the network.

More Adobe CVEs

Sources