---
id: CVE-2026-27301
title: >-
  Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based
  Buffer Overflow vulnerability that could lead to memory exposure
summary: >-
  Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based
  Buffer Overflow vulnerability that could lead to memory exposure. An attacker
  could leverage this vulnerability to disclose sensitive information stored in
  memory.…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-122
vendor: adobe
product: framemaker
affected:
  - framemaker < 2022.9
patched:
  - framemaker 2022.9
published: '2026-04-14'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27301'
references:
  - url: 'https://helpx.adobe.com/security/products/framemaker/apsb26-36.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00295
epssPercentile: 0.19639
ingestedAt: '2026-07-26T10:11:59.857Z'
---

## Overview

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `framemaker < 2022.9`

## Remediation

Upgrade past the affected range:

- `framemaker 2022.9`
