CVE-2026-47963
published 2026-06-16CVE-2026-47963: DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.17%
6.1th percentile
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dng_sdk | <= 1.7.1 2536 | — |
| adobe | dng_software_development_kit | < 1.7.1.2611 | 1.7.1.2611 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
ghsa_unreviewed·2026-06-16
CVE-2026-47963 [MEDIUM] CWE-125 DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe DNG SDK up to 1.7.1 2536 File out-of-bounds (apsb26-67)
vuldb·2026-06-16·CVSS 5.5
CVE-2026-47963 [MEDIUM] Adobe DNG SDK up to 1.7.1 2536 File out-of-bounds (apsb26-67)
A vulnerability labeled as problematic has been found in Adobe DNG SDK up to 1.7.1 2536. This vulnerability affects unknown code of the component File Handler. Executing a manipulation can lead to out-of-bounds read.
The identification of this vulnerability is CVE-2026-47963. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published