Junglewise Threat Intelligence

CVE-2026-27301: Adobe FrameMaker heap buffer overflow in file processing

CVE-2026-27301 · Severity: medium · CVSS 5.5 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security flaw that could allow unauthorized access to system memory. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could result in the exposure of sensitive information stored in the computer's memory, potentially compromising user data or system security.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe FrameMaker versions 2022.8 and earlier. The vulnerability is triggered when the application processes a specially crafted file, leading to an out-of-bounds memory access. This is a local attack vector requiring user interaction (UI:R), as a victim must manually open the malicious document. Successful exploitation allows an attacker to read sensitive information from the process memory, though it does not directly grant code execution or data modification capabilities. Adobe has addressed this in newer versions, and users are advised to update to version 2022.9 or later.

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats