Junglewise Threat Intelligence

CVE-2026-34639: Adobe Media Encoder out-of-bounds write

CVE-2026-34639 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Media Encoder. Vendors: Adobe.

Executive brief

Adobe Media Encoder, a professional video and audio processing application, is affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or install software with the same permissions as the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Media Encoder versions 26.0.2, 25.6.4 and earlier. The flaw is triggered when the application processes a malformed file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution within the security context of the current user. The attack vector is local, requiring a user to manually open a malicious file (User Interaction: Required). Adobe has addressed this in newer versions, and users are advised to update to the latest available releases.

Affected products

  • Adobe Media Encoder 26.0.2, 25.6.4 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats