
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27300 is an Access of Uninitialized Pointer vulnerability (CWE-824) in Adobe FrameMaker that can lead to memory exposure and sensitive information disclosure. It affects Adobe FrameMaker versions 2022.8 and earlier (all versions prior to 2022.9). Adobe disclosed and patched the vulnerability on April 14, 2026, as part of its April 2026 security update (APSB26-36). It carries a CVSS v3.1 base score of 5.5 (Medium), though the broader advisory context notes multiple Critical-severity issues in the same update (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-824 (Access of Uninitialized Pointer), where Adobe FrameMaker fails to properly initialize a pointer before accessing it during file parsing operations. An attacker can exploit this flaw by crafting a malicious FrameMaker document that, when opened by a victim, triggers the uninitialized pointer access and results in memory exposure. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted malicious file. No public proof-of-concept exploit code has been identified (Adobe Advisory, GitHub Advisory).
Successful exploitation of CVE-2026-27300 results in a high confidentiality impact, allowing an attacker to disclose sensitive information from memory. Integrity and availability are not affected by this specific vulnerability. The primary risk is exposure of sensitive data residing in process memory at the time a malicious file is opened, which could include credentials, document contents, or other in-memory artifacts (Adobe Advisory).
.fm or FrameMaker-format files received via email or downloaded from untrusted sources.FrameMaker.exe) crashing or exhibiting abnormal behavior (e.g., access violations) when opening specific files.Adobe has released a patch in Adobe FrameMaker version 2022.9, which resolves CVE-2026-27300. Users should update to version 2022.9 or later immediately via the Adobe update mechanism or by downloading from the Adobe portal. As an interim workaround, restrict local access to systems running vulnerable versions, educate users not to open FrameMaker files from untrusted sources, and consider implementing application whitelisting. The patch details are available in Adobe Security Bulletin APSB26-36 (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products patched in April 2026 could allow for arbitrary code execution, referencing the broader APSB26-36 bulletin. Coverage was largely limited to automated vulnerability tracking platforms and security digest services, with no notable independent researcher commentary or significant social media discussion identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."