CVE-2026-27294Disclosure(adobe / framemaker)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch adobe framemaker systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • framemaker
  • windows

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-15); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
framemakerwindows

1 version affected across 2 products

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-14: 2Mentions · 2026-04-15: 3Mentions · 2026-04-23: 1Mentions · 2026-07-31: 1Exploit Tool / Code · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 3Technical Details · 2026-04-23: 1Technical Details · 2026-07-31: 104-1404-1504-2307-31
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure1Patch1
2026-04-153
Disclosure3
2026-04-231
Patch1
2026-07-311
Patch1
Full discourse7 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The post lists multiple newly disclosed CVEs across several vendors, details their technical impact, and points to available patches or remediation guidance, particularly noting Microsoft’s April 2026 update.

    000321.4K
    11.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-27294 (CVSS 7.8) affects Adobe FrameMaker 2022.8 & earlier. Out-of-bounds read vulnerability enables code execution via malicious file. User interaction required. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/KcwPDgqpjk

    Post summary

    The tweet announces a high‑severity CVE‑2026‑27294 vulnerability in Adobe FrameMaker that can lead to code execution via a malicious file and recommends immediate patching. No exploit code, active exploitation, or false‑positive claim is presented.

    0000047
    99 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-27294 (CVSS 7.8) Adobe FrameMaker ≤2022.8 out-of-bounds read flaw enables code execution via crafted file. Requires user interaction. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/z4c9Q4vkeu

    Post summary

    The tweet announces that Adobe FrameMaker versions ≤2022.8 are affected by a high‑severity CVE‑2026‑27294 that allows code execution via crafted files, and urges immediate patching.

    0000053
    26 followersView on X
  • dbugs@ptdbugs
    Disclosure

    Adobe Framemaker | Out-of-bounds Read (CWE-125) CVE: CVE-2026-27294 PT ID: PT-2026-32943 Vendor: Adobe Product: Adobe Framemaker CVSS: 7.8 Credits: n/a Description: Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27294 • https://helpx.adobe.com/security/products/framemaker/apsb26-36.html #dbugs_vuln

    Post summary

    Adobe Framemaker versions 2022.8 and earlier are affected by an out‑of‑bounds read that could lead to code execution, as disclosed with a patch available via Adobe's advisory.

    0000063
    797 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27294 Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the en… https://www.cve.org/CVERecord?id=CVE-2026-27294

    Post summary

    The text announces an out-of-bounds read vulnerability in Adobe Framemaker 2022.8 or earlier, but offers no exploit code, patch information, or evidence of active exploitation.

    0000068
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27294 Out-of-Bounds Read Vulnerability in Adobe FrameMaker 2022.8 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27294

    Post summary

    CVE-2026-27294 is an out‑of‑bounds read vulnerability impacting Adobe FrameMaker versions up to 2022.8, with details available via the Vulmon link.

    0000046
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-27294 Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted… CVSS 7.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-27294 #Adobe #CyberSecurity #InfoSec

    Post summary

    The post highlights a high‑severity out‑of‑bounds read flaw in Adobe Framemaker versions 2022.8 and earlier, providing basic technical details and a CVSS score, but omits PoC, exploit code, or remediation information.

    000000
    144 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeframemaker---
OSmicrosoftwindows---

Explore more