Executive brief
Adobe Dreamweaver, a professional tool for web design and development, is affected by a security flaw in one of its underlying components. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized commands on the user's computer. This could lead to a full system compromise, data theft, or the installation of malware.
Technical details
Adobe Dreamweaver Desktop (versions 21.7 and earlier) contains a vulnerability categorized as a Dependency on Vulnerable Third-Party Component. The flaw exists because the application relies on an external library or module that contains a known security defect. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) indicates a local attack vector with a 'Changed' scope, suggesting the exploit can impact components beyond the immediate application environment. Users are advised to update to the latest version provided by Adobe.
Affected products
- Adobe Dreamweaver Desktop 21.7 and earlier
Timeline
- 2026-06-09: disclosed: Initial disclosure by Adobe and NVD publication.
- 2026-06-09: advisory: Adobe security bulletin APSB26-62 released.