CVE-2026-21272
published 2026-01-13CVE-2026-21272: Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An…
PriorityP345high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.19%
9.3th percentile
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data into files on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dreamweaver | < 21.7 | 21.7 |
| adobe | dreamweaver_desktop | <= 21.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21271 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21271 [HIGH] CVE-2026-21271 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21271 :
Adobe Dreamweaver vulnerability analysis and mitigation
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Source : NVD
## 8.6
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Adobe Dreamweaver
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:adobe:dreamweaver
Sources
Windows Severity HIGH Has Fix
Wiz
CVE-2026-21267 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21267 [HIGH] CVE-2026-21267 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21267 :
Adobe Dreamweaver vulnerability analysis and mitigation
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Source : NVD
## 8.6
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Adobe Dreamweaver
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:dreamwea
Wiz
CVE-2026-21274 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21274 [HIGH] CVE-2026-21274 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21274 :
Adobe Dreamweaver vulnerability analysis and mitigation
Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures and execute unauthorized code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Dreamweaver
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.2
Exploitation Probability (EPSS) 0.1
Affected packages
Wiz
CVE-2026-21268 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21268 [HIGH] CVE-2026-21268 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21268 :
Adobe Dreamweaver vulnerability analysis and mitigation
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Source : NVD
## 8.6
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Adobe Dreamweaver
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:adobe:dreamweaver
Sources
Windows Severity HIGH Has Fix
Wiz
CVE-2026-21272 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21272 [HIGH] CVE-2026-21272 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21272 :
Adobe Dreamweaver vulnerability analysis and mitigation
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data into files on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Source : NVD
## 8.6
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Adobe Dreamweaver
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.7
Exploitation Probability (EPSS) N/A
Affected packages and l
2026-01-13
Published