Junglewise Threat Intelligence

CVE-2026-76192: Adobe InDesign Desktop null pointer dereference

CVE-2026-76192 · Severity: medium · CVSS 5.5 · Published 2026-09-22

Technologies: Adobe InDesign Desktop. Vendors: Adobe.

Executive brief

Adobe InDesign Desktop, a desktop publishing application, contains a null pointer dereference vulnerability that can be triggered when opening a malicious file. An attacker can exploit this flaw to crash the application, causing a denial-of-service condition and disrupting the user's work. Exploitation requires the victim to open a specially crafted file.

Technical details

A null pointer dereference in InDesign Desktop allows an attacker to trigger an application crash through a malicious file. The vulnerability requires user interaction (opening a crafted document) and does not permit remote code execution. The flaw results in denial-of-service by making the application unavailable.

Affected products

  • Adobe InDesign Desktop

Timeline

  • 2026-09-22: disclosed

References

Related threats