Junglewise Threat Intelligence

CVE-2026-21318: Adobe After Effects out-of-bounds write in file handling

CVE-2026-21318 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects, a professional video editing and motion graphics software used by creative teams, contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code on a user's computer. The vulnerability is triggered when a victim opens a malicious file, making it a social engineering risk for organizations relying on After Effects for content production.

Technical details

The vulnerability is an out-of-bounds write flaw in Adobe After Effects versions 25.6 and earlier, affecting file handling operations. Exploitation requires user interaction—specifically, the victim must open a malicious file crafted to trigger the out-of-bounds write condition. Successful exploitation results in arbitrary code execution in the context of the current user, granting an attacker full system access with the privileges of that user. The CVSS v3 score is 7.8 (high severity) and the issue is not currently known to be exploited in the wild. A patch is expected from Adobe; users should update to versions after 25.6 when available.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats