CVE-2026-27258
published 2026-04-14CVE-2026-27258: DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.3th percentile
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt memory, causing the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dng_sdk | <= 1.7.1 2502 | — |
| adobe | dng_software_development_kit | <= 1.7.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85g7-96qr-w5x4: DNG SDK versions 1
ghsa_unreviewed·2026-04-14
CVE-2026-27258 [MEDIUM] CWE-787 GHSA-85g7-96qr-w5x4: DNG SDK versions 1
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt memory, causing the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe DNG SDK up to 1.7.1 2502 File out-of-bounds write (apsb26-41)
vuldb·2026-04-14·CVSS 5.5
CVE-2026-27258 [MEDIUM] Adobe DNG SDK up to 1.7.1 2502 File out-of-bounds write (apsb26-41)
A vulnerability marked as critical has been reported in Adobe DNG SDK up to 1.7.1 2502. This affects an unknown part of the component File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2026-27258. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published