Skip to content

SB2026041701

Cybersecurity-Help.Cz April 17, 2026

The vulnerability exists due to out-of-bounds read in Adobe InCopy when parsing a crafted file. A remote attacker can trick the victim into opening a crafted file to execute arbitrary code.

User interaction is required to open a crafted file.

2) Out-of-bounds write (CVE-ID: CVE-2026-27264)

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in Adobe InCopy when parsing a crafted file. A remote attacker can trick the victim into opening a crafted file to execute arbitrary code.

User interaction is required to open a crafted file.

Install update from vendor's website.