Junglewise Threat Intelligence

CVE-2026-48270: Adobe Premiere Pro out-of-bounds write

CVE-2026-48270 · Severity: high · CVSS 7.8 · Published 2026-07-14

Executive brief

Adobe Premiere Pro, a professional video editing application, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the execution of malicious software on the victim's computer.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Premiere Pro. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the logged-in user. The attack vector is local, requiring a user to manually open a malicious file (User Interaction: Required). Adobe has addressed this in versions 26.3 and 25.6.6.

Affected products

  • Adobe Premiere Pro <= 26.2.2, <= 25.6.5

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats