SB2026041703 - Multiple vulnerabilities in Adobe Framemaker
Published: April 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 secuirty vulnerabilities.
1) Untrusted search path (CVE-ID: CVE-2026-27290)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to untrusted search path in Adobe FrameMaker when loading resources from an untrusted search path. A remote attacker can place a malicious file in a searched path to execute arbitrary code.
User interaction is required to open malicious content.
2) Use-after-free (CVE-ID: CVE-2026-27292)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
3) Heap-based buffer overflow (CVE-ID: CVE-2026-27293)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
4) Out-of-bounds read (CVE-ID: CVE-2026-27294)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds read in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
5) Out-of-bounds write (CVE-ID: CVE-2026-27295)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
6) Integer underflow (CVE-ID: CVE-2026-27296)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer underflow in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
7) Integer underflow (CVE-ID: CVE-2026-27297)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer underflow in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
8) Type Confusion (CVE-ID: CVE-2026-27298)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to type confusion in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required to open crafted content.
9) Improper input validation (CVE-ID: CVE-2026-27299)
The vulnerability allows a remote attacker to read arbitrary files.
The vulnerability exists due to improper input validation in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to read arbitrary files.
User interaction is required to open crafted content.
10) Access of Uninitialized Pointer (CVE-ID: CVE-2026-27300)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to access of uninitialized pointer in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to disclose sensitive information.
User interaction is required to open crafted content.
11) Heap-based buffer overflow (CVE-ID: CVE-2026-27301)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to heap-based buffer overflow in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to disclose sensitive information.
User interaction is required to open crafted content.
Remediation
Install update from vendor's website.