
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21358 is a heap-based buffer overflow vulnerability in Adobe InDesign Desktop that can result in application denial-of-service. Affected versions include InDesign Desktop 21.1 and earlier (in the 21.x branch) and 20.5.1 and earlier (in the 20.x branch). The vulnerability was disclosed on February 10, 2026, with Adobe releasing a patch the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), occurring when InDesign Desktop processes a specially crafted malicious file. An attacker exploits this by inducing a victim to open a malicious document, triggering an out-of-bounds write to heap memory that causes the application to crash. The attack vector is local (the file must be opened on the victim's machine), requires no privileges, but does require user interaction. No public proof-of-concept or technical write-up has been identified at this time (Adobe Advisory).
Successful exploitation results in a denial-of-service condition, specifically crashing the Adobe InDesign Desktop application. There is no impact on confidentiality or integrity — the vulnerability's availability impact is limited to the application process itself. Lateral movement or data exfiltration are not associated with this vulnerability based on current analysis (Adobe Advisory).
Adobe has released patched versions to address this vulnerability: users on the 21.x branch should update to InDesign Desktop 21.2 or later, and users on the 20.x branch should update to version 20.5.2 or later. As a general precaution, users should avoid opening InDesign files from untrusted or unknown sources. Endpoint protection solutions capable of detecting malicious documents may provide additional defense-in-depth (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in February 2026, including this issue, flagging the potential for arbitrary code execution across the broader Adobe patch batch. Tenable released detection plugins (Nessus plugin 298520) to identify vulnerable InDesign installations. No significant researcher commentary or social media discussion specific to CVE-2026-21358 has been observed, consistent with its medium severity and lack of active exploitation (CIS Advisory, Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."