---
id: CVE-2026-21353
title: >-
  DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or
  Wraparound vulnerability that could result in arbitrary code execution in the
  context of the current user
summary: >-
  DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or
  Wraparound vulnerability that could result in arbitrary code execution in the
  context of the current user. Exploitation of this issue requires user
  interactio…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: adobe
product: dng_software_development_kit
affected:
  - dng_software_development_kit < 1.7.2
patched:
  - dng_software_development_kit 1.7.2
published: '2026-02-10'
updated: '2026-08-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21353'
references:
  - url: 'https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00187
epssPercentile: 0.07322
ingestedAt: '2026-08-27T21:08:16.984Z'
---

## Overview

DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `dng_software_development_kit < 1.7.2`

## Remediation

Upgrade past the affected range:

- `dng_software_development_kit 1.7.2`
