Junglewise Threat Intelligence

CVE-2026-48372: Adobe Format Plugins heap overflow in file processing

CVE-2026-48372 · Severity: high · CVSS 7.8 · Published 2026-07-28

Technologies: Adobe Format Plugins. Vendors: Adobe.

Executive brief

Adobe Format Plugins is a component used to handle various file formats within Adobe software. A security flaw in this component allows an attacker to take control of a user's computer if the user is tricked into opening a specially crafted malicious file. This could lead to the theft of sensitive data, unauthorized software installation, or a complete system compromise.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe Format Plugins versions 2026.05 and earlier. The vulnerability is triggered when the application fails to properly validate input while processing a malformed file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, potentially achieving arbitrary code execution in the context of the current user. The issue is addressed in version 2026.07.

Affected products

  • Adobe Format Plugins <= 2026.05

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References

Related threats