CVE-2026-21351

7.8

Adobe · After Effects

Adobe After Effects versions 25.6 and earlier contain a Use After Free vulnerability that allows arbitrary code execution via a malicious file.

Executive summary

A critical Use After Free vulnerability in Adobe After Effects 25.6 and earlier could allow an attacker to achieve arbitrary code execution through user interaction.

Vulnerability

This is a Use After Free vulnerability (CWE-416) that occurs during memory management. An attacker can trigger this flaw by enticing a user to open a specially crafted malicious file, which then executes arbitrary code in the context of the current user.

Business impact

Successful exploitation of this vulnerability permits an attacker to execute arbitrary code on the host system, potentially leading to a complete compromise of the workstation. Given the CVSS score of 7.8, this represents a high-severity risk to organizational data confidentiality, integrity, and availability. Compromised systems may be used as a foothold for lateral movement within the corporate network.

Remediation

Immediate Action: Update all installations of Adobe After Effects to version 25.6.4 or 26.0 immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review system logs for signs of application crashes or unusual file access patterns, particularly when opening files from untrusted sources.

Compensating Controls: Implement endpoint protection software configured to scan files upon access and utilize application whitelisting to restrict the execution of unauthorized binaries.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this flaw and the potential for arbitrary code execution necessitate immediate patching across all affected systems. IT administrators should prioritize the deployment of Adobe After Effects version 25.6.4 or 26.0 to eliminate the vulnerability. Users should be reminded to exercise caution when opening files from untrusted or unknown sources until all systems are fully updated.

More Adobe CVEs

Sources