Junglewise Threat Intelligence

CVE-2026-34640: Adobe Media Encoder integer overflow in file processing

CVE-2026-34640 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Media Encoder. Vendors: Adobe.

Executive brief

Adobe Media Encoder, a professional video processing application, is affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the installation of malicious software in the context of the logged-in user.

Technical details

An integer overflow vulnerability (CWE-190) exists in Adobe Media Encoder versions 25.6.4, 26.0.2, and earlier. The flaw occurs during the processing of malformed media files, where improper bounds checking leads to a wraparound condition. An attacker can leverage this to achieve arbitrary code execution with the privileges of the current user. The attack vector is local and requires user interaction, specifically the opening of a malicious file. Adobe has addressed this in newer versions (25.6.5 and 26.2).

Affected products

  • Adobe Media Encoder <= 25.6.4, 26.0.0 to 26.0.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats