Junglewise Threat Intelligence

CVE-2026-27287: Adobe InCopy out-of-bounds read in file parsing

CVE-2026-27287 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe InCopy. Vendors: Adobe.

Executive brief

Adobe InCopy, a professional writing and editing software, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized code on the victim's computer. This could lead to a full system compromise, data theft, or disruption of business operations.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Adobe InCopy versions 20.5.2, 21.2 and earlier. The flaw is triggered during the parsing of specifically crafted files, leading to a read past the end of an allocated memory structure. While primarily a memory exhaustion or information disclosure class of bug, Adobe notes this specific vulnerability can be leveraged to achieve arbitrary code execution in the context of the current user. Exploitation requires local access and user interaction, specifically that a victim must be induced into opening a malicious file. Adobe has addressed this in newer versions (20.5.3 and 21.3).

Affected products

  • Adobe InCopy 20.5.2, 21.2 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe published APSB26-33

References

Related threats