Junglewise Threat Intelligence

CVE-2026-27293: Adobe FrameMaker heap overflow in file parsing

CVE-2026-27293 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands or install malware on the user's computer. This could lead to a full compromise of the victim's workstation and any data accessible to that user.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe FrameMaker versions 2022.8 and earlier. The vulnerability is triggered when the application fails to properly validate input data while parsing a document, leading to memory corruption. An attacker can exploit this by convincing a user to open a specifically crafted malicious file. Successful exploitation allows for arbitrary code execution in the context of the current user. Adobe has addressed this in version 2022.9 (APSB26-36).

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: advisory: Initial disclosure by Adobe and NVD publication
  • 2026-04-14: patched: Adobe released version 2022.9 to address the issue

References

Related threats