
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27298 is a type confusion vulnerability in Adobe Framemaker versions 2022.8 and earlier that can result in arbitrary code execution in the context of the current user. The vulnerability was published on April 14, 2026, and a patch was released the same day as part of Adobe's April 2026 security update (APSB26-36). It carries a CVSS v3.1 base score of 7.8 (High), reflecting its local attack vector and requirement for user interaction (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type, or 'Type Confusion'), meaning the application incorrectly handles a resource as a different type than intended, leading to memory corruption or unexpected behavior. Exploitation requires a victim to open a specially crafted malicious file, making this a file-parsing vulnerability with a local attack vector. No privileges are required on the part of the attacker, but user interaction is mandatory — typically achieved through social engineering to deliver the malicious document (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe Framemaker, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files, modify data, or cause application crashes. Since execution occurs in the context of the current user, the blast radius is limited to that user's permissions, though it could serve as a foothold for further lateral movement in environments where Framemaker users have elevated privileges (Adobe Advisory).
.fm or related file format) that triggers the type confusion vulnerability during parsing.%APPDATA%, %TEMP%) shortly after opening a Framemaker document; presence of unknown executables or scripts dropped by the Framemaker process.cmd.exe, powershell.exe, curl.exe, or scripting interpreters); Framemaker process making unexpected network connections.Adobe has released a patch in Adobe Framemaker version 2022.9, which addresses this vulnerability. Users should update to version 2022.9 or later immediately via the Adobe update mechanism or by downloading the update from Adobe's official site (Adobe Advisory). As interim mitigations, organizations should educate users to avoid opening Framemaker files from untrusted or unexpected sources, implement application whitelisting, and consider restricting file access permissions where feasible.
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). Security aggregators and threat intelligence platforms such as Red Packet Security and Beyond Machines covered the April 2026 Adobe patch release, highlighting this CVE among others. No significant independent researcher commentary or social media discussion beyond routine patch reporting has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."