Junglewise Threat Intelligence

CVE-2026-47976: Adobe Media Encoder out-of-bounds write code execution

CVE-2026-47976 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Adobe Media Encoder. Vendors: Adobe.

Executive brief

Adobe Media Encoder, a professional video processing application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized software or access sensitive data with the same permissions as the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Media Encoder versions 26.2.2 and 25.6.5 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. The attack vector is local, requiring a user to manually open a malicious file (User Interaction: Required). Adobe has released patches in versions 26.3 and 25.6.6 to address this issue.

Affected products

  • Adobe Media Encoder <= 26.2.2, <= 25.6.5

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-72
  • 2026-07-14: disclosed: CVE-2026-47976 published to NVD

References

Related threats