CVE-2026-21322

7.8

Adobe · After Effects

Adobe After Effects versions 25.6 and earlier contain an out-of-bounds read vulnerability that may allow a local attacker to execute arbitrary code via a malicious file.

Executive summary

Adobe After Effects versions 25.6 and earlier are vulnerable to an out-of-bounds read flaw that could lead to arbitrary code execution if a user is tricked into opening a crafted file.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) occurring during the parsing of crafted files. Successful exploitation requires user interaction, as the victim must open a malicious file, but it does not require prior authentication.

Business impact

The ability for an attacker to execute code in the context of the current user poses a significant risk to system integrity and data confidentiality. With a CVSS score of 7.8, this high-severity vulnerability could facilitate unauthorized access to sensitive projects, intellectual property, or the host machine itself. Organizations relying on After Effects for creative workflows must treat this as a priority to prevent potential workstation compromise.

Remediation

Immediate Action: Update Adobe After Effects to version 25.6.4 or 26.0 to incorporate the necessary security fixes provided by the vendor.

Proactive Monitoring: Monitor system logs for unusual crashes or unexpected process behavior associated with After Effects during file ingestion.

Compensating Controls: Implement strict email and file-sharing policies to prevent users from opening untrusted or unsolicited project files from unknown sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, administrators should prioritize the deployment of the patched versions of After Effects across all creative workstations. Ensuring that software is updated to version 25.6.4 or 26.0 is the only effective way to remediate this memory-related vulnerability. Users should remain vigilant regarding the source of any project files they open until the update is applied.

More Adobe CVEs

Sources