Security Incident – macOS Vulnerability Affecting InDesign Generation Server
Resolved
Aug 17, 2026 at 8:55am UTC
We identified unauthorized access to one of our InDesign generation servers, where a cryptocurrency mining application was installed.
The incident resulted from exploitation of a recently disclosed macOS vulnerability, CVE-2026-65400.
The affected server has been isolated and secured, the unauthorized software and access have been removed, and the vulnerability has been patched. As an additional precaution, we will fully wipe and rebuild the server during our upcoming maintenance window.
The affected server only processes cached generation data and does not contain customer personal data, credentials, or access codes. No customer data was exposed.
We continue to monitor our environment and have found no indication that other systems were affected.
Affected services