Junglewise Threat Intelligence

CVE-2026-21329: Adobe After Effects use-after-free vulnerability

CVE-2026-21329 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects is a professional video and motion graphics application used by creative professionals. A use-after-free vulnerability in versions 25.6 and earlier could allow an attacker to execute arbitrary code with the privileges of the user running the application if they trick the user into opening a specially crafted file. This could lead to data theft, system compromise, or unauthorized access to creative projects.

Technical details

The vulnerability is a use-after-free memory corruption issue in After Effects. The attack requires user interaction—specifically, a victim must open a malicious file—making social engineering or file delivery the primary attack vector. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user. The vulnerability affects After Effects version 25.6 and earlier. Patch status and availability are not detailed in the provided advisory.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats