---
id: CVE-2026-71399
title: >-
  Adobe XD is affected by a Buffer Overflow vulnerability that could result in
  arbitrary code execution in the context of the current user
summary: >-
  Adobe XD is affected by a Buffer Overflow vulnerability that could result in
  arbitrary code execution in the context of the current user. An attacker could
  exploit this vulnerability to execute arbitrary code. Exploitation of this
  issue …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: adobe
product: xd
affected:
  - xd < 61
patched:
  - xd 61
published: '2026-08-25'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:01:17.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71399'
references:
  - url: 'https://helpx.adobe.com/security/products/xd/apsb26-125.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00337
epssPercentile: 0.24461
ingestedAt: '2026-09-15T15:39:12.864Z'
---

## Overview

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `xd < 61`

## Remediation

Upgrade past the affected range:

- `xd 61`
