PT-2026-32702 · Adobe · Indesign

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-27286

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions InDesign Desktop versions prior to 20.5.3 and 21.3
Description A heap-based buffer overflow occurs when a program writes more data to a heap-allocated memory block than it can hold. This issue allows an attacker to disclose sensitive information stored in memory. Exploitation requires user interaction, specifically the opening of a malicious file.
Recommendations Update to version 20.5.3 or later. Update to version 21.3 or later.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-05397
CVE-2026-27286

Affected Products

Indesign