CVE-2026-21325

7.8

Adobe · After Effects

Adobe After Effects is affected by an out-of-bounds read vulnerability that allows for arbitrary code execution when processing a maliciously crafted file.

Executive summary

Adobe After Effects versions 25.6 and earlier contain an out-of-bounds read vulnerability that permits remote code execution through user interaction.

Vulnerability

This vulnerability involves an out-of-bounds read (CWE-125) triggered when the software parses a crafted file, allowing an attacker to read past allocated memory structures. Successful exploitation requires an unauthenticated attacker to convince a user to open a malicious file, which may result in code execution within the context of the current user.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational assets, as an attacker could gain control over the victim's workstation, access sensitive files, or install persistent malware. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the potential for total loss of confidentiality, integrity, and availability for the affected user session.

Remediation

Immediate Action: Update Adobe After Effects to version 25.6.4, 26.0, or later to address the underlying memory management flaw.

Proactive Monitoring: Monitor workstation endpoint logs for suspicious process spawning behavior, particularly those initiated by the After Effects executable.

Compensating Controls: Implement file integrity monitoring and restrict the execution of untrusted media files from unknown sources to reduce the risk of successful exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, it is imperative that all systems running Adobe After Effects are updated to the patched versions immediately. Organizations should prioritize patching on systems that frequently handle external or untrusted media files to mitigate the risk of compromise.

More Adobe CVEs

Sources