Junglewise Threat Intelligence

CVE-2026-47979: Adobe Media Encoder out-of-bounds read

CVE-2026-47979 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Adobe Media Encoder. Vendors: Adobe.

Executive brief

Adobe Media Encoder, a professional video processing application, is affected by a security flaw that could allow an attacker to access sensitive information. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to the unauthorized disclosure of sensitive data stored in the computer's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Adobe Media Encoder versions 26.2.2 and earlier, as well as 25.6.5 and earlier. The flaw occurs when the application processes a specially crafted file, leading the software to read data past the end of the intended buffer. An attacker can exploit this by convincing a user to open a malicious file, potentially resulting in the disclosure of sensitive information from the process memory. The vulnerability has been addressed in versions 26.3 and 25.6.6. The attack vector is local and requires user interaction.

Affected products

  • Adobe Media Encoder <= 26.2.2, <= 25.6.5

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-72
  • 2026-07-14: disclosed

References

Related threats