CVE-2026-21332
published 2026-02-10CVE-2026-21332: InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.15%
4.9th percentile
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | indesign | < 20.5.2 | 20.5.2 |
| adobe | indesign | >= 21.0 < 21.2 | 21.2 |
| adobe | indesign_desktop | <= 20.5.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21278 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21278 [MEDIUM] CVE-2026-21278 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21278 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published January 13, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows Se
Wiz
CVE-2026-21276 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21276 [HIGH] CVE-2026-21276 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21276 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows Severity HIGH Has Fix Added at: Jan 14, 2
Wiz
CVE-2026-21304 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21304 [MEDIUM] CVE-2026-21304 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21304 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows Severity HIGH Has Fix Added at: Jan 14, 2026
W
Wiz
CVE-2026-21358 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21358 [MEDIUM] CVE-2026-21358 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21358 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adob
Wiz
CVE-2026-21275 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21275 [HIGH] CVE-2026-21275 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21275 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows Severity HIGH Has Fix Added at: Jan 14, 2
Wiz
CVE-2026-21332 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21332 [MEDIUM] CVE-2026-21332 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21332 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows
Wiz
CVE-2026-21277 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21277 [HIGH] CVE-2026-21277 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21277 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows Severity HIGH Has Fix Added at: Jan 14, 2026
W
Wiz
CVE-2026-21357 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21357 [MEDIUM] CVE-2026-21357 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21357 :
Adobe InDesign vulnerability analysis and mitigation
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe InDesign
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:indesign
Sources
Windows Severity HIGH Has Fix Added at: Feb 11, 2026
Wi
2026-02-10
Published