Junglewise Threat Intelligence

CVE-2026-21324: Adobe After Effects out-of-bounds read in file parsing

CVE-2026-21324 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects contains an out-of-bounds read vulnerability when opening specially crafted files. An attacker can exploit this by tricking a user into opening a malicious file, potentially allowing arbitrary code execution with the privileges of the user running the application. This poses a risk to organizations using After Effects for video production and design work.

Technical details

The vulnerability is an out-of-bounds read flaw in After Effects' file parsing logic that occurs when processing a crafted input file. When parsing the malicious file, the application reads memory past the end of an allocated structure, which can be leveraged to disclose sensitive information or achieve code execution in the context of the current user. The attack requires user interaction—a victim must be tricked into opening the malicious file. Versions 25.6 and earlier are affected, and a patch is expected from Adobe.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats