CVE-2026-21323

7.8

Adobe · After Effects

Adobe After Effects is affected by a Use After Free vulnerability that may allow an attacker to achieve arbitrary code execution upon opening a malicious file.

Executive summary

Adobe After Effects versions 25.6 and earlier are vulnerable to a critical Use After Free flaw that could lead to arbitrary code execution if a user opens a specially crafted file.

Vulnerability

This vulnerability is a Use After Free (CWE-416) condition that occurs when the application incorrectly handles memory. The attack requires user interaction, specifically the opening of a malicious file, and operates in the context of the current authenticated user.

Business impact

The ability for an attacker to execute arbitrary code poses a severe risk to organizational security, potentially leading to full system compromise, unauthorized data access, and the installation of persistent malware. With a CVSS score of 7.8, this vulnerability represents a high-severity threat that necessitates immediate attention to prevent unauthorized control over workstations running the affected software.

Remediation

Immediate Action: Update Adobe After Effects to version 25.6.4 or 26.0 immediately to resolve the underlying memory management flaw.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected file access activity following the use of After Effects.

Compensating Controls: Ensure that endpoint detection and response tools are configured to scan files upon opening and restrict the execution of untrusted media files from unknown sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a significant risk to the integrity of systems running Adobe After Effects. Administrators should prioritize the deployment of the vendor-provided updates to versions 25.6.4 or 26.0 across all relevant workstations to eliminate this attack vector. Failure to patch leaves end users susceptible to compromise via socially engineered file delivery.

More Adobe CVEs

Sources