Junglewise Threat Intelligence

CVE-2026-34637: Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code ex

CVE-2026-34637 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Premiere Pro. Vendors: Adobe.

Executive brief

Adobe Premiere Pro, a professional video editing application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data, system instability, or the execution of malicious software.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Premiere Pro versions 26.0.2, 25.6.4 and earlier. The flaw occurs when the application improperly handles memory during the processing of specially crafted files. An attacker can exploit this by delivering a malicious file to a target user; upon opening the file, the application may write data beyond the end of an intended buffer. This memory corruption can be leveraged to achieve arbitrary code execution with the privileges of the logged-in user. Users are advised to update to versions 25.6.5 or 26.2 to mitigate this risk.

Affected products

  • Adobe Premiere Pro 26.0.2, 25.6.4 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats