Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

Adobe InDesign: Opening Malicious Files Can Crash App or Run Malware

CVE-2026-27238
Summary

Adobe InDesign versions 20.5.2 and earlier are vulnerable to a security issue that could cause the app to crash or run malicious code on your computer if you open a poisoned file. This means you could accidentally download malware or have your computer taken over if you open a malicious file in InDesign. To stay safe, update to the latest version of InDesign.

Original title
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Explo...
Original description
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd CVSS3.1 7.8
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 14 Apr 2026 · Updated: 14 Apr 2026 · First seen: 14 Apr 2026