
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27287 is an out-of-bounds read vulnerability in Adobe InCopy that can result in arbitrary code execution when a victim opens a specially crafted file. It affects InCopy versions 20.5.2 and earlier (in the 20.x branch) and versions 21.2 and earlier (in the 21.x branch), running on both Windows and macOS. Adobe disclosed and patched the vulnerability on April 14, 2026. It carries a CVSS v3.1 base score of 7.8 (High), assigned by Adobe Systems Incorporated (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), triggered during the parsing of a crafted file by InCopy. When processing the malicious file, the application reads past the end of an allocated memory structure, which can be leveraged to achieve code execution in the context of the current user. Exploitation requires local access in the sense that the attacker must deliver a malicious file to the victim, who must then open it — no network-based exploitation path exists. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the logged-in InCopy user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access sensitive documents, install malware, or use the compromised session as a foothold for lateral movement within the organization. The scope is limited to the local user context, but given InCopy's use in publishing and editorial workflows, sensitive intellectual property and document content could be at risk (Adobe Advisory).
.icml or related format) that triggers the out-of-bounds read during parsing, potentially enabling control over program execution flow.Adobe has released patched versions addressing this vulnerability: InCopy 20.5.3 (for users on the 20.x branch) and InCopy 21.3 (for users on the 21.x branch). Users should update immediately via the Creative Cloud desktop application or Adobe's official download channels. As a supplementary measure, organizations should educate users to avoid opening InCopy files from untrusted or unexpected sources, and consider implementing file-type restrictions at email gateways where feasible (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple Adobe product vulnerabilities disclosed in April 2026, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). General community coverage has been limited to automated vulnerability digest services and threat intelligence aggregators, with no notable independent researcher commentary or significant social media discussion identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."