Junglewise Threat Intelligence

CVE-2026-21325: Adobe After Effects out-of-bounds read in file parsing

CVE-2026-21325 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects, a professional video editing and motion graphics software, contains an out-of-bounds memory read vulnerability when processing specially crafted files. An attacker can exploit this by tricking a user into opening a malicious project file, potentially allowing arbitrary code execution with the user's privileges. This could lead to system compromise, data theft, or lateral movement within an organization.

Technical details

The vulnerability is an out-of-bounds read in After Effects' file parsing logic, triggered when processing a crafted file that causes the parser to read past the end of an allocated memory structure. The attack requires user interaction: a victim must open the malicious file in After Effects. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. Versions 25.6 and earlier are affected. Adobe has released security updates to address this issue.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats