DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
References
| Link | Resource |
|---|---|
| https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html | Vendor Advisory |
Configurations
History
13 Feb 2026, 20:37
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html - Vendor Advisory | |
| CPE | cpe:2.3:a:adobe:dng_software_development_kit:*:*:*:*:*:*:*:* | |
| First Time |
Adobe
Adobe dng Software Development Kit |
10 Feb 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-10 19:15
Updated : 2026-02-13 20:37
NVD link : CVE-2026-21353
Mitre link : CVE-2026-21353
CVE.ORG link : CVE-2026-21353
JSON object : View
Products Affected
adobe
- dng_software_development_kit
CWE
CWE-190
Integer Overflow or Wraparound
