Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

InDesign: Malicious File Can Expose Sensitive Information

CVE-2026-27286
Summary

Adobe InDesign Desktop versions 20.5.2 and earlier are vulnerable to a security risk. If you open a malicious file with InDesign, an attacker could access sensitive information stored on your computer. Update to the latest version of InDesign to protect your data.

Original title
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to di...
Original description
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd CVSS3.1 5.5
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 14 Apr 2026 · Updated: 15 Apr 2026 · First seen: 14 Apr 2026