Junglewise Threat Intelligence

CVE-2026-21277: Adobe InDesign heap-based buffer overflow

CVE-2026-21277 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Adobe InDesign. Vendors: Adobe.

Executive brief

Adobe InDesign is a professional design and layout software used by creative teams to produce digital and print media. A heap-based buffer overflow vulnerability allows attackers to achieve arbitrary code execution on a user's computer by tricking them into opening a specially crafted malicious file. This could enable unauthorized access to sensitive project files, system data, and provide a foothold for further attacks.

Technical details

A heap-based buffer overflow vulnerability exists in Adobe InDesign that permits arbitrary code execution within the context of the user running the application. The vulnerability is triggered when a user opens a crafted malicious file, indicating the flaw likely resides in file parsing or processing logic. The attack requires user interaction (opening a file) but no authentication bypass or elevated privileges are necessary. An attacker can achieve arbitrary code execution on the victim's system with the privileges of the logged-in user. Adobe has addressed this issue in patched versions beyond 19.5.5 and 21.0.

Affected products

  • Adobe InDesign 19.5.5, 21.0 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats