CVE-2026-21325
7.8Adobe · After Effects
Adobe After Effects is affected by an out-of-bounds read vulnerability that allows for arbitrary code execution when processing a maliciously crafted file.
Executive summary
Adobe After Effects versions 25.6 and earlier contain an out-of-bounds read vulnerability that permits remote code execution through user interaction.
Vulnerability
This vulnerability involves an out-of-bounds read (CWE-125) triggered when the software parses a crafted file, allowing an attacker to read past allocated memory structures. Successful exploitation requires an unauthenticated attacker to convince a user to open a malicious file, which may result in code execution within the context of the current user.
Business impact
The potential for arbitrary code execution poses a significant risk to organizational assets, as an attacker could gain control over the victim's workstation, access sensitive files, or install persistent malware. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the potential for total loss of confidentiality, integrity, and availability for the affected user session.
Remediation
Immediate Action: Update Adobe After Effects to version 25.6.4, 26.0, or later to address the underlying memory management flaw.
Proactive Monitoring: Monitor workstation endpoint logs for suspicious process spawning behavior, particularly those initiated by the After Effects executable.
Compensating Controls: Implement file integrity monitoring and restrict the execution of untrusted media files from unknown sources to reduce the risk of successful exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, it is imperative that all systems running Adobe After Effects are updated to the patched versions immediately. Organizations should prioritize patching on systems that frequently handle external or untrusted media files to mitigate the risk of compromise.