CVE-2026-21353

7.8

Adobe · DNG Software Development Kit (SDK)

Adobe DNG SDK is vulnerable to an integer overflow that can lead to arbitrary code execution when a user opens a malicious file.

Executive summary

Adobe DNG SDK versions 1.7.1.2410 and earlier are vulnerable to an integer overflow, posing a risk of arbitrary code execution to users who interact with malicious files.

Vulnerability

This vulnerability is a CWE-190 Integer Overflow or Wraparound flaw within the DNG SDK. An unauthenticated attacker can achieve arbitrary code execution in the context of the current user if the victim is tricked into opening a specially crafted malicious file.

Business impact

The ability for an attacker to execute arbitrary code on a user machine creates a significant risk of malware installation, data exfiltration, or complete system compromise. With a CVSS score of 7.8, this high-severity flaw requires urgent attention to prevent potential lateral movement within the network. Organizations relying on software that integrates the DNG SDK should prioritize this update to protect end-user workstations.

Remediation

Immediate Action: Update the DNG SDK integration to version 1.7.1.2471 or later as provided in the official Adobe security advisory.

Proactive Monitoring: Monitor system logs for unexpected process execution or abnormal application crashes occurring when users open image files.

Compensating Controls: Use endpoint protection solutions to scan incoming files for malicious patterns and restrict the execution of untrusted software on sensitive systems.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a clear threat to user integrity. Administrators must ensure that all applications utilizing the affected DNG SDK are patched to version 1.7.1.2471 or higher without delay to mitigate the risk of exploitation.

More Adobe CVEs

Sources