Description
Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow (CWE‑122) and an out‑of‑bounds write (CWE‑787) in Adobe’s Format Plugins that can lead to arbitrary code execution within the context of the current user. The flaw arises when the plugin processes certain file types without proper bounds checking, allowing an attacker to overflow a heap buffer and execute attacker‑controlled code. Successful exploitation could compromise the session of the victim, granting the attacker full control with the user's privileges.

Affected Systems

Adobe Format Plugins. The advisory does not specify affected versions, so administrators should check all existing installations and apply the latest Adobe release that addresses this flaw.

Risk and Exploitability

The CVSS score is 7.8, reflecting a high severity vulnerability, while the EPSS score is below 1 %, suggesting a low likelihood of immediate broad exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction—specifically, a victim must open a malicious file containing the crafted payload. Although the need for user action lowers the overall risk to organizations, the potential for arbitrary code execution remains a serious threat if users are deceived into opening suspicious documents.

Generated by OpenCVE AI on August 12, 2026 at 04:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Format Plugins update that patches the buffer overflow
  • If an update is not yet available, block processing of the vulnerable file types via file‑type filters or group policy
  • Educate users to avoid opening unsolicited or unknown files and to verify file sources before opening

Generated by OpenCVE AI on August 12, 2026 at 04:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe format Plugins
Vendors & Products Adobe
Adobe format Plugins

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Format Plugins | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Format Plugins
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-28T17:59:59.491Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48372

cve-icon Vulnrichment

Updated: 2026-07-28T17:59:56.947Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T18:17:20.747

Modified: 2026-08-05T19:11:11.260

Link: CVE-2026-48372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T05:00:09Z

Weaknesses