CVE-2026-47964
published 2026-06-16CVE-2026-47964: DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
9.9th percentile
DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dng_sdk | <= 1.7.1 2536 | — |
| adobe | dng_software_development_kit | < 1.7.1.2611 | 1.7.1.2611 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe DNG SDK up to 1.7.1 2536 File heap-based overflow (apsb26-67)
vuldb·2026-06-16·CVSS 7.8
CVE-2026-47964 [HIGH] Adobe DNG SDK up to 1.7.1 2536 File heap-based overflow (apsb26-67)
A vulnerability marked as critical has been reported in Adobe DNG SDK up to 1.7.1 2536. This issue affects some unknown processing of the component File Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2026-47964. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-06-16
CVE-2026-47964 [HIGH] CWE-122 DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.
DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published