
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34707 is a Heap-based Buffer Overflow vulnerability (CWE-122) in Adobe InCopy that could result in arbitrary code execution in the context of the current user. It affects Adobe InCopy versions 21.3, 20.5.3, and earlier on both Windows and macOS platforms. The vulnerability was disclosed and patched on June 9, 2026, via Adobe security bulletin APSB26-59. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), where a buffer allocated in the heap portion of memory can be overwritten due to insufficient bounds checking during file parsing. An attacker exploits this by crafting a malicious InCopy file that, when opened by a victim, triggers the overflow and allows arbitrary code execution. The attack vector is local (the file must be delivered and opened on the target system), requires no privileges, but does require user interaction — specifically, the victim must open the malicious file. No public proof-of-concept or technical write-up detailing the specific file parsing routine affected has been published (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Adobe InCopy, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive documents, modify or delete files, or install malware within the user's security context. While the scope is unchanged (limited to the compromised user's context), a successful attack could serve as an initial foothold for further lateral movement if the victim has elevated privileges (Adobe Advisory, GitHub Advisory).
.icml, .incd, .incx) files received via email or downloaded from untrusted sources; new or modified files in user profile directories shortly after opening an InCopy document.cmd.exe, powershell.exe, bash, curl, wget); InCopy process exhibiting unexpected network connections.Adobe released patched versions of InCopy on June 9, 2026, via security bulletin APSB26-59. Users should update to InCopy version 20.5.4 (for the 20.x branch) or version 21.4 (for the 21.x branch). As an interim workaround, users should avoid opening InCopy files from untrusted or unknown sources, and administrators may consider disabling file type associations for InCopy document formats where the application is not actively needed (Adobe Advisory).
The vulnerability was noted in Adobe's June 2026 patch cycle, which covered multiple products, and was referenced in a CISA vulnerability bulletin (SB26-166) and a Fortress SRM threat update for June 2026. Community discussion appears limited, with a brief mention on Mastodon. No significant independent researcher commentary or media coverage has been identified beyond standard vulnerability aggregator reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."