Junglewise Threat Intelligence

CVE-2026-34636: Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code ex

CVE-2026-34636 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Premiere Pro. Vendors: Adobe.

Executive brief

Adobe Premiere Pro, a professional video editing application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious project or media file. If successful, the attacker could execute unauthorized commands or install software with the same permissions as the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Premiere Pro. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution in the context of the current user. The attack vector is local, requiring the victim to manually open a malicious file (User Interaction: Required). Adobe has addressed this in updated versions of the software.

Affected products

  • Adobe Premiere Pro <= 25.6.4, 26.0.0 to 26.0.2

Timeline

  • 2026-05-12: advisory: Initial advisory published by Adobe
  • 2026-05-12: disclosed

References

Related threats