
InCopy | Out-of-bounds Write (CWE-787) CVE: CVE-2026-34631 PT ID: PT-2026-32935 Vendor: Adobe Product: InCopy CVSS: 7.8 Credits: n/a Description: InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34631 • https://helpx.adobe.com/security/products/incopy/apsb26-33.html #dbugs_vuln
Post summary
Adobe’s InCopy versions 20.5.2, 21.2 and earlier contain an out‑of‑bounds write vulnerability that could lead to arbitrary code execution when a user opens a malicious file; a vendor patch is available.


