
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21275 is an Access of Uninitialized Pointer vulnerability (CWE-824) in Adobe InDesign Desktop that can result in arbitrary code execution in the context of the current user. It affects InDesign Desktop versions 21.0, 19.5.5 and earlier (specifically, all versions before 20.5.1 and versions 21.0.x before 21.1) on both Windows and macOS. The vulnerability was disclosed on January 13, 2026, with an initial NVD analysis completed on January 14, 2026. It carries a CVSS v3.1 base score of 7.8 (High), as assigned by Adobe (Adobe Advisory, NVD).
The vulnerability is classified as CWE-824 (Access of Uninitialized Pointer), meaning the application dereferences a pointer that has not been properly initialized during file parsing operations. An attacker exploits this by crafting a malicious InDesign file that triggers the uninitialized pointer access when opened by the victim, potentially redirecting execution flow to attacker-controlled code. The attack vector is local (the file must be delivered and opened on the victim's system), requires no privileges, but does require user interaction — specifically, the victim must open the malicious file. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, NVD).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running InDesign Desktop, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution can perform any action the victim user is authorized to perform, including accessing sensitive documents, installing malware, or pivoting to other systems accessible from the victim's account. Both Windows and macOS platforms running affected InDesign versions are at risk (Adobe Advisory, NVD).
%APPDATA%, ~/Library/) shortly after opening an InDesign file; suspicious InDesign-related files received from unknown or untrusted sources.cmd.exe, powershell.exe, bash, curl, python) on Windows or macOS.Adobe has released patched versions to address this vulnerability: users on the 19.x/20.x branch should update to InDesign Desktop 20.5.1 or later, and users on the 21.x branch should update to 21.1 or later. As a workaround, users should be advised to only open InDesign files from trusted, verified sources and to exercise caution with files received via email or downloaded from the internet. Organizations should consider deploying application allowlisting or sandboxing controls to limit the impact of potential exploitation (Adobe Advisory).
The CIS (Center for Internet Security) issued an advisory noting that multiple Adobe vulnerabilities patched in January 2026, including this one, could allow for arbitrary code execution. The Zero Day Initiative's January 2026 security update review also covered this vulnerability as part of Adobe's patch batch. Social media coverage was limited, with brief mentions on platforms such as Bluesky by security news aggregators. Overall community reaction has been measured given the absence of active exploitation or a public PoC (CIS Advisory, ZDI Review).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."