CVE-2026-34631Disclosure(adobe / incopy)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch adobe incopy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incopy
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
incopymacoswindows

1 version affected across 3 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-15: 3Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 304-15
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets5 URLs
Full discourse3 posts
  • dbugs@ptdbugs
    Patch

    InCopy | Out-of-bounds Write (CWE-787) CVE: CVE-2026-34631 PT ID: PT-2026-32935 Vendor: Adobe Product: InCopy CVSS: 7.8 Credits: n/a Description: InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34631 • https://helpx.adobe.com/security/products/incopy/apsb26-33.html #dbugs_vuln

    Post summary

    Adobe’s InCopy versions 20.5.2, 21.2 and earlier contain an out‑of‑bounds write vulnerability that could lead to arbitrary code execution when a user opens a malicious file; a vendor patch is available.

    0000058
    797 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34631 InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the curr… https://www.cve.org/CVERecord?id=CVE-2026-34631

    Post summary

    The post announces CVE-2026-34631 as an out-of-bounds write flaw in Adobe InCopy that could lead to arbitrary code execution. No exploit, patch, or active exploitation details are provided.

    0000085
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34631 Out-of-Bounds Write Vulnerability in Adobe InCopy 21.2 and Earlie... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34631 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A brief announcement of CVE-2026-34631, an out‑of‑bounds write vulnerability affecting Adobe InCopy 21.2 and earlier, with only a link to the vuln details and no PoC, exploit, or patch information.

    0000047
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeincopy---
OSapplemacos---
OSmicrosoftwindows---

Explore more