CVE-2026-21357Disclosure(adobe / indesign)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe indesign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • indesign
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
indesignmacoswindows

1 version affected across 3 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-13: 1Mentions · 2026-02-17: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-17: 102-1002-1302-17
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-131
General1
2026-02-171
Patch1
Full discourse3 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple vulnerabilities in multiple #Adobe products. CVE-2026-21357 CVSS: 7.8. These can lead to arbitrary code execution! See: https://helpx.adobe.com/security/products/after_effects/apsb26-15.html https://helpx.adobe.com/security/products/audition/apsb26-14.html https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html https://helpx.adobe.com/security/products/indesign/apsb26-17.html https://helpx.adobe.com/security/products/substance3d_stager/apsb26-20.html #Patch #Patch #Patch

    Post summary

    Multiple Adobe products are affected by CVE-2026-21357 (CVSS 7.8), enabling arbitrary code execution; Adobe has released patches as detailed in the advisory links.

    03011332
    7.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-21357 ❗ CVE-2026-21335 ❗ CVE-2026-21318 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-adobe-4/ https://t.co/yjR3EDwiuW

    Post summary

    The post lists three Adobe CVEs with links for further information but offers no PoC, exploit details, patch info, or technical description.

    00000102
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21357 InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the con… https://www.cve.org/CVERecord?id=CVE-2026-21357

    Post summary

    CVE-2026-21357 reports a heap-based buffer overflow in InDesign Desktop that could allow arbitrary code execution, but no PoC, exploit, or patch is referenced.

    0000097
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeindesign---
OSapplemacos---
OSmicrosoftwindows---

Explore more