CVE-2019-7107: Adobe Indesign

Critical severity, CVSS 9.8. EPSS: 28.9% chance of exploitation in the next 30 days.

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

Affected products

  • Adobe Indesign: up to and including 14.0.1

Published 2019-05-23. Last modified 2026-06-17.