CVE-2026-48267
published 2026-07-06CVE-2026-48267: DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.14%
3.7th percentile
DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dng_sdk | <= 1.7.1 2536 | — |
| adobe | dng_software_development_kit | < 1.7.1.2611 | 1.7.1.2611 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service.
ghsa_unreviewed·2026-07-06
CVE-2026-48267 [MEDIUM] CWE-476 DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service.
DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe DNG SDK null pointer dereference
vuldb·2026-07-06·CVSS 5.5
CVE-2026-48267 [MEDIUM] Adobe DNG SDK null pointer dereference
A vulnerability classified as problematic was found in Adobe DNG SDK. Affected by this vulnerability is an unknown functionality. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-48267. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-06
Published