Junglewise Threat Intelligence

CVE-2026-21357: Adobe InDesign Desktop heap-based buffer overflow

CVE-2026-21357 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe InDesign Desktop. Vendors: Adobe.

Executive brief

Adobe InDesign Desktop is a professional layout and design application used to create printed and digital publications. A heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on a user's system if they trick the user into opening a specially crafted malicious document, potentially leading to data theft or system compromise.

Technical details

The vulnerability is a heap-based buffer overflow in InDesign Desktop versions 21.1, 20.5.1 and earlier. The flaw can be exploited through user interaction—specifically, by inducing a victim to open a malicious file. Successful exploitation allows arbitrary code execution with the privileges of the current user. The vulnerability requires no network access or authentication, but depends on social engineering to deliver the malicious file. Adobe has assigned this a CVSS score of 7.8. A patch is available through Adobe's security advisory APSB26-17.

Affected products

  • Adobe InDesign Desktop 21.1, 20.5.1 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats