Junglewise Threat Intelligence

CVE-2026-27294: Adobe FrameMaker out-of-bounds read in file parsing

CVE-2026-27294 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands or take control of the user's computer. This could lead to the theft of sensitive data or a complete compromise of the affected workstation.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw is triggered during the parsing of a specifically crafted file, leading to a read past the end of an allocated memory structure. While typically associated with information disclosure, this specific vulnerability is reported to allow for arbitrary code execution in the context of the current user. Exploitation requires local access and user interaction, specifically that a victim must manually open the malicious file. Adobe has addressed this in newer versions, and users are advised to update to version 2022.9 or later.

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats