CVE-2026-21268 is an Improper Input Validation vulnerability affecting Adobe Dreamweaver Desktop versions 21.6 and earlier on Windows and macOS. This high-severity vulnerability (CVSS 8.6) allows for arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community discussion, indicating potential interest. Organizations using affected Dreamweaver versions should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.7CPE matchmatch criteria | cpe:2.3:a:adobe:dreamweaver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.