Junglewise Threat Intelligence

CVE-2026-27297: Adobe FrameMaker integer underflow arbitrary code execution

CVE-2026-27297 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands or software on the victim's computer. This could lead to a full system compromise, data theft, or the installation of malware in the context of the logged-in user.

Technical details

An integer underflow (CWE-191) exists in Adobe FrameMaker versions 2022.8 and earlier. The vulnerability occurs during the parsing of malformed files, where a wrap-around error leads to memory corruption. An attacker can exploit this by convincing a user to open a specially crafted document, potentially achieving arbitrary code execution in the context of the current user. The attack vector is local (AV:L) because it requires the victim to download and open a file, and user interaction (UI:R) is a prerequisite for successful exploitation.

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: advisory: Initial advisory published by Adobe and NVD.

References

Related threats