Junglewise Threat Intelligence

CVE-2026-21353: Adobe DNG SDK integer overflow in file parsing

CVE-2026-21353 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Dng Software Development Kit, Adobe DNG SDK. Vendors: Adobe.

Executive brief

Adobe DNG SDK is a library used by developers to read and process Digital Negative (DNG) image files. Versions 1.7.1 2410 and earlier contain an integer overflow vulnerability that allows an attacker to execute arbitrary code on a user's system if they convince the user to open a malicious DNG image file. This could lead to unauthorized access to sensitive data, system compromise, or malware installation.

Technical details

The vulnerability is an integer overflow or wraparound in Adobe DNG SDK versions 1.7.1 2410 and earlier, affecting the file parsing logic. The integer overflow occurs in a component responsible for processing DNG image metadata or pixel data, leading to a heap or stack buffer overflow that enables arbitrary code execution. The attack requires user interaction—a victim must open a malicious DNG file in an application linked against the vulnerable SDK. No authentication or special privileges are needed beyond opening the file. Patches or mitigations should be available from Adobe for affected SDK versions.

Affected products

  • Adobe DNG SDK 1.7.1 2410 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats