Junglewise Threat Intelligence

CVE-2026-21351: Adobe After Effects use-after-free vulnerability

CVE-2026-21351 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects versions 25.6 and earlier contain a use-after-free vulnerability that could allow attackers to execute arbitrary code with the privileges of the user running the application. An attacker would need to trick a victim into opening a specially crafted file to trigger the exploit, making this a practical risk for creative professionals who frequently work with files from untrusted sources.

Technical details

A use-after-free vulnerability exists in Adobe After Effects where an application function attempts to access memory after it has been freed, potentially allowing execution of attacker-controlled code. The vulnerability affects versions 25.6 and earlier. Exploitation requires user interaction—specifically, the victim must open a malicious file (such as a project file) in After Effects. When triggered, an attacker gains code execution in the context of the current user. A patch or update addressing this issue is likely available from Adobe.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats