CVE-2026-27291
7.8Adobe · InDesign Desktop
Adobe InDesign Desktop contains an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious file.
Executive summary
A critical out-of-bounds write vulnerability in Adobe InDesign Desktop allows for arbitrary code execution upon the opening of a maliciously crafted file by an end user.
Vulnerability
The software is susceptible to an out-of-bounds write (CWE-787) flaw that can be triggered when a user opens a specially crafted file. Successful exploitation allows an attacker to execute arbitrary code within the security context of the current user, requiring successful social engineering or user interaction.
Business impact
The ability for an attacker to execute arbitrary code poses a significant risk to organizational data integrity and system confidentiality. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the potential for complete loss of control over the affected workstation and potential lateral movement within the network.
Remediation
Immediate Action: Update Adobe InDesign Desktop to version 21.3, 20.5.3, or later to incorporate the vendor-provided security fixes.
Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or unexpected file system modifications originating from the InDesign application.
Compensating Controls: Implement strict email filtering and web gateway policies to prevent the delivery of untrusted or unknown InDesign document formats to end users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential code execution, organizations should prioritize the deployment of the vendor patches to all affected systems. Users should be cautioned against opening InDesign files from untrusted sources until the update is applied across the environment.