Junglewise Threat Intelligence

CVE-2026-21350: Adobe After Effects NULL pointer dereference

CVE-2026-21350 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects is a professional video editing and motion graphics application. A NULL pointer dereference vulnerability in versions 25.6 and earlier allows an attacker to crash the application by sending a specially crafted file, causing service disruption and loss of work for users who open the malicious file.

Technical details

A NULL pointer dereference vulnerability exists in Adobe After Effects 25.6 and earlier. The vulnerability is triggered when the application processes a malicious file, causing a crash that results in a denial-of-service condition. Exploitation requires user interaction—specifically, a victim must open the malicious file. No patch availability information is provided in the advisory, though the CVE publication date suggests vendor notification has occurred.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats