
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21268 is an Improper Input Validation vulnerability (CWE-20) in Adobe Dreamweaver Desktop that allows arbitrary code execution in the context of the current user. It affects Dreamweaver Desktop versions 21.6 and earlier on both Windows and macOS platforms. The vulnerability was disclosed on January 13, 2026, with Adobe releasing a patch the same day. It carries a CVSS v3.1 base score of 8.6 (High), assigned by Adobe Systems Incorporated (Adobe Advisory, NVD).
The vulnerability stems from insufficient input validation when Dreamweaver Desktop processes file content, classified as CWE-20 (Improper Input Validation). The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted malicious file. Notably, the vulnerability has a changed scope (S:C), meaning successful exploitation can impact resources beyond the vulnerable Dreamweaver component itself, potentially escaping the application's security boundary. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, NVD).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user running Dreamweaver Desktop, resulting in high impact to confidentiality, integrity, and availability. Because the scope is changed, the attacker may be able to affect resources beyond the Dreamweaver process itself, potentially enabling access to sensitive files, modification of system files, and disruption of system availability. The attack requires social engineering to trick a user into opening a malicious file, limiting mass exploitation but making targeted attacks against Dreamweaver users feasible (Adobe Advisory, NVD).
cmd.exe, powershell.exe, /bin/bash, curl, wget) following the opening of an external file.Adobe has released Dreamweaver Desktop version 21.7 to address this vulnerability; users should update immediately via the Creative Cloud desktop application or Adobe's official download channels. As a workaround prior to patching, users should avoid opening Dreamweaver project files or other supported file types received from untrusted or unknown sources, particularly those delivered via email or downloaded from suspicious websites. Organizations should also consider user awareness training to reduce the risk of social engineering attacks targeting Dreamweaver users (Adobe Advisory).
The vulnerability received coverage from The Hacker Wire, which published an article on the Dreamweaver RCE issue and shared it via Mastodon and Infosec.exchange social channels. The Center for Internet Security (CIS) included it in an advisory covering multiple Adobe vulnerabilities that could allow arbitrary code execution. The Zero Day Initiative's January 2026 Security Update Review, summarized by BeyondMachines, also noted the vulnerability. Community reaction has been measured given the lack of active exploitation and the requirement for user interaction (The Hacker Wire, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."