Junglewise Threat Intelligence

CVE-2026-34690: Adobe After Effects stack-based buffer overflow

CVE-2026-34690 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe After Effects. Vendors: Adobe.

Executive brief

Adobe After Effects, a professional video editing and visual effects application, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to execute unauthorized commands on the user's computer. This could lead to a full system compromise, data theft, or the installation of malware in the context of the logged-in user.

Technical details

A stack-based buffer overflow (CWE-121) exists in Adobe After Effects versions 25.6.5, 26.2.1, and earlier. The vulnerability is triggered when the application improperly handles memory while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious project or asset file, leading to arbitrary code execution in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R). Adobe has released security updates (APSB26-78) to address this issue in versions 25.6.6 and 26.3.

Affected products

  • Adobe After Effects <= 25.6.5, 26.0 to <= 26.2.1

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Initial advisory published by Adobe
  • 2026-07-14: patched: Updated advisory and version information provided by vendor

References

Related threats