
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27286 is a Heap-based Buffer Overflow vulnerability (CWE-122) in Adobe InDesign Desktop that can lead to memory disclosure. It affects InDesign Desktop versions 20.5.2, 21.2, and earlier (specifically versions prior to 20.5.3 in the 20.x branch and prior to 21.3 in the 21.x branch). Adobe disclosed and patched this vulnerability on April 14, 2026, as part of its April 2026 security update cycle. It carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).
The vulnerability is classified as a Heap-based Buffer Overflow (CWE-122), where improper memory management during file parsing allows heap memory to be read beyond intended boundaries. An attacker exploits this by crafting a malicious InDesign file that, when opened by a victim, triggers the overflow and exposes sensitive data from process memory. The attack vector is local (the file must be delivered and opened on the victim's machine), requires no privileges, but does require user interaction — the victim must open the malicious file. No public proof-of-concept or technical write-up has been identified at this time (Adobe Advisory).
Successful exploitation results in memory disclosure, allowing an attacker to read sensitive information from the InDesign process memory space. The impact is limited to confidentiality — there is no integrity or availability impact based on the CVSS assessment. Because the attack is local and requires user interaction, the blast radius is constrained to the victim's workstation, though exposed memory contents could include credentials, document data, or other sensitive in-memory artifacts (Adobe Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2026-27286. The EPSS score is approximately 0.021%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to convince a user to open a specially crafted file, which raises the practical bar for attackers (Adobe Advisory).
.indd, .idml, or other InDesign-format files received via email or downloaded from untrusted sources.InDesign.exe) with heap-related fault addresses.Adobe has released patched versions addressing this vulnerability: InDesign Desktop 20.5.3 (for the 20.x branch) and InDesign Desktop 21.3 (for the 21.x branch). Users should update immediately via the Adobe Creative Cloud desktop application. As a general workaround, users should avoid opening InDesign files from untrusted or unknown sources until the patch is applied (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products patched in April 2026 could allow for arbitrary code execution, grouping CVE-2026-27286 among the broader set of Adobe April 2026 updates (CIS Advisory). No significant independent researcher commentary or social media discussion specific to this CVE has been identified, consistent with its medium severity rating and lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."