Junglewise Threat Intelligence

CVE-2026-34707: Adobe InCopy heap overflow in file parsing

CVE-2026-34707 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe InCopy. Vendors: Adobe.

Executive brief

Adobe InCopy, a professional writing and editing software, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could take control of the computer and run unauthorized commands. This could lead to the theft of sensitive data or a complete system compromise.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe InCopy versions 21.3, 20.5.3 and earlier. The vulnerability is triggered when the application fails to properly validate input while parsing a malicious file, leading to memory corruption. An attacker can exploit this by convincing a victim to open a specifically crafted document. Successful exploitation allows for arbitrary code execution in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R).

Affected products

  • Adobe InCopy 21.3, 20.5.3 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats