Junglewise Threat Intelligence

CVE-2026-27296: Adobe FrameMaker integer underflow code execution

CVE-2026-27296 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software execution, data theft, or full system compromise in the context of the logged-in user.

Technical details

An integer underflow (CWE-191) vulnerability exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw occurs during the processing of specially crafted files, where a wrap-around error can lead to memory corruption. An attacker can exploit this by delivering a malicious file to a victim; upon opening the file, the vulnerability triggers, potentially allowing arbitrary code execution in the context of the current user. The attack requires user interaction (UI:R) and local delivery (AV:L), but provides high impact to confidentiality, integrity, and availability. Adobe has addressed this in version 2022.9.

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: advisory: Initial disclosure by Adobe and NVD publication
  • 2026-04-14: patched: Adobe released version 2022.9 to address the issue

References

Related threats