Executive brief
After Effects is a professional video and animation editing software used for creating visual effects and motion graphics. Versions 25.6 and earlier contain an out-of-bounds write flaw that could allow an attacker to execute arbitrary code on a user's system if the user opens a specially crafted malicious file. This could compromise the integrity of a designer's work, expose sensitive project files, or enable broader system compromise.
Technical details
The vulnerability is an out-of-bounds write in After Effects version 25.6 and earlier, which occurs when the application processes specially crafted input files. The flaw allows an attacker to write data beyond the bounds of an allocated buffer, potentially enabling arbitrary code execution with the privileges of the current user. Exploitation requires user interaction—specifically, the victim must open a malicious file in After Effects. The CVSS score of 7.8 reflects the high impact of code execution balanced against the user-interaction requirement. Patches are expected to be available via Adobe's standard security updates (APSB26-15).
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed: CVE-2026-21327 published