Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2023 articles · 105826 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-21352PATCHED
adobe · dng_software_development_kit

DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu

Description

DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Products

VendorProductVersions
adobedng_software_development_kit< 1.7.2

References

  • https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html(Vendor Advisory)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available1.7.2
CWECWE-787
Published2/10/2026
Last enriched3d ago
Trending Score0
Source articles0
Independent0
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-27309EXP
Substance3D - Stager | Use After Free (CWE-416)
Trending: 34
PRE-CVE
Multiple vulnerabilities in Adobe Creative Cloud applications
Trending: 20
MEDIUMCVE-2026-21314
Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive informati
MEDIUMCVE-2026-27217
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerabilit
MEDIUMCVE-2026-27223
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable f

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 10, 2026
Patch Available
Feb 13, 2026
Discovered by ZDM
Mar 26, 2026