CVE-2026-27269

7.8

Adobe · Premiere Pro

Adobe Premiere Pro versions 25.5 and earlier are vulnerable to an out-of-bounds read flaw that could allow an attacker to execute arbitrary code via a malicious file.

Executive summary

Adobe Premiere Pro contains a critical out-of-bounds read vulnerability that allows for arbitrary code execution if a user is tricked into opening a specially crafted file.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) triggered when the application parses a malicious file. Successful exploitation requires user interaction to open the file, at which point an attacker can achieve code execution within the context of the current user.

Business impact

The ability for an unprivileged attacker to execute arbitrary code poses a severe risk to organizational security. Because the exploit runs in the context of the current user, an attacker could potentially gain unauthorized access to sensitive project data, install persistent malware, or move laterally within the network. With a CVSS score of 7.8, this vulnerability represents a high-severity threat that necessitates immediate patching to prevent potential system compromise and data theft.

Remediation

Immediate Action: Update Adobe Premiere Pro to version 25.6 or later to incorporate the vendor-supplied fix.

Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected file access patterns that may indicate an attempt to trigger the out-of-bounds read.

Compensating Controls: Implement endpoint protection solutions to scan incoming media files for malicious content before they are opened by Adobe Premiere Pro users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution, organizations should prioritize updating all instances of Adobe Premiere Pro to the latest available version. Security teams should communicate the risk of opening untrusted files to end users until the update is applied across the environment.

More Adobe CVEs

Sources