Junglewise Threat Intelligence

CVE-2026-34706: Adobe InCopy out-of-bounds write vulnerability

CVE-2026-34706 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe InCopy. Vendors: Adobe.

Executive brief

Adobe InCopy, a professional writing and editing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access, system disruption, or full compromise of the user's workstation.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe InCopy versions 21.3, 20.5.3 and earlier. The flaw occurs when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. The attack vector is local, requiring the victim to manually open a malicious document (User Interaction required). Adobe has addressed this in security bulletin APSB26-59.

Affected products

  • Adobe InCopy 21.3, 20.5.3 and earlier

Timeline

  • 2026-06-09: advisory: Adobe published security bulletin APSB26-59
  • 2026-06-09: disclosed: CVE-2026-34706 published to NVD

References

Related threats