Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2963 articles · 161899 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-34707EXPLOITEDPATCHED
adobe · incopy

InCopy | Heap-based Buffer Overflow (CWE-122)

Description

InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Products

VendorProductVersions
adobeincopy0

References

  • https://helpx.adobe.com/security/products/incopy/apsb26-59.html(vendor-advisory)

Related News (1 articles)

Tier C
VulDB5h ago
CVE-2026-34707 | Adobe InCopy up to 20.5.3/21.3 File heap-based overflow (apsb26-59)
→ No new info (linked only)
CVSS 3.17.8 CRITICAL
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://helpx.adobe.com/security/products/incopy/apsb26-59.html
CWECWE-122
PublishedJun 9, 2026
Last enriched4h agov2
Tags
CVE-2026-34707
Trending Score49
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34700EXP
InDesign Desktop | Out-of-bounds Write (CWE-787)
Trending: 51
HIGHCVE-2026-34697EXP
InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
Trending: 51
HIGHCVE-2026-34699EXP
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Trending: 51
HIGHCVE-2026-34698EXP
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Trending: 51
HIGHCVE-2026-48293EXP
InDesign Desktop | Out-of-bounds Write (CWE-787)
Trending: 51

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Actively Exploited
Jun 9, 2026
Patch Available
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: severity, activelyExploited, tags
Jun 9, 2026

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated severity to CRITICAL, marked as actively exploited, and added CVE-2026-34707 as a new tag.

severityactivelyExploitedtags
via VulDB
v15h ago

Initial creation