CVE-2026-27291

7.8

Adobe · InDesign Desktop

Adobe InDesign Desktop contains an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious file.

Executive summary

A critical out-of-bounds write vulnerability in Adobe InDesign Desktop allows for arbitrary code execution upon the opening of a maliciously crafted file by an end user.

Vulnerability

The software is susceptible to an out-of-bounds write (CWE-787) flaw that can be triggered when a user opens a specially crafted file. Successful exploitation allows an attacker to execute arbitrary code within the security context of the current user, requiring successful social engineering or user interaction.

Business impact

The ability for an attacker to execute arbitrary code poses a significant risk to organizational data integrity and system confidentiality. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the potential for complete loss of control over the affected workstation and potential lateral movement within the network.

Remediation

Immediate Action: Update Adobe InDesign Desktop to version 21.3, 20.5.3, or later to incorporate the vendor-provided security fixes.

Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or unexpected file system modifications originating from the InDesign application.

Compensating Controls: Implement strict email filtering and web gateway policies to prevent the delivery of untrusted or unknown InDesign document formats to end users.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential code execution, organizations should prioritize the deployment of the vendor patches to all affected systems. Users should be cautioned against opening InDesign files from untrusted sources until the update is applied across the environment.

More Adobe CVEs

Sources