Junglewise Threat Intelligence

CVE-2026-34643: Adobe After Effects out-of-bounds write

CVE-2026-34643 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe After Effects. Vendors: Adobe.

Executive brief

Adobe After Effects, a professional video editing and visual effects application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software installation, data theft, or complete system compromise in the context of the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe After Effects versions 26.0, 25.6.4 and earlier. The flaw is triggered when the application processes a malformed file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. Exploitation requires local delivery of a malicious file and user interaction (opening the file). Adobe has addressed this issue in updated versions of the software.

Affected products

  • Adobe After Effects 26.0, 25.6.4 and earlier

Timeline

  • 2026-05-12: advisory: Initial disclosure by Adobe and NVD

References

Related threats