Junglewise Threat Intelligence

CVE-2026-48292: Adobe Format Plugins heap buffer overflow

CVE-2026-48292 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Format Plugins. Vendors: Adobe.

Executive brief

Adobe Format Plugins versions 1.1.2 and earlier are affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software execution, potentially compromising sensitive data or system stability.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe Format Plugins versions 1.1.2 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, potentially achieving arbitrary code execution in the context of the current user. The attack vector is classified as local with required user interaction. Adobe has addressed this in security bulletin APSB26-65.

Affected products

  • Adobe Format Plugins 1.1.2 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-65 published

References

Related threats