Junglewise Threat Intelligence

CVE-2026-27280: Adobe DNG SDK out-of-bounds write

CVE-2026-27280 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Dng Software Development Kit, Adobe DNG SDK. Vendors: Adobe.

Executive brief

Adobe's DNG SDK is a library used by image editing and processing applications to handle DNG (Digital Negative) image files. An out-of-bounds write vulnerability in versions 1.7.1 2471 and earlier could allow an attacker to execute arbitrary code if a user opens a specially crafted malicious DNG file, potentially compromising the user's system and any data accessible from their account.

Technical details

The vulnerability is an out-of-bounds write flaw in Adobe DNG SDK versions 1.7.1 2471 and earlier. The root cause lies in insufficient bounds checking when processing DNG image files, allowing writes beyond allocated memory. Exploitation requires user interaction: a victim must open a malicious DNG file in an application using the vulnerable SDK. Successful exploitation permits arbitrary code execution within the context of the current user. No user authentication is required, and the attack surface includes any application that uses the vulnerable DNG SDK library to parse or process DNG images.

Affected products

  • Adobe DNG SDK 1.7.1 2471 and earlier

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: APSB26-30

References

Related threats