Junglewise Threat Intelligence

CVE-2026-48366: Adobe Media Encoder out-of-bounds write

CVE-2026-48366 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Adobe Media Encoder. Vendors: Adobe.

Executive brief

Adobe Media Encoder, a professional video processing application, is affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data or the ability to run malicious software with the same permissions as the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Media Encoder. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. The attack vector is local, requiring user interaction (UI:R) to open the malicious file. Adobe has addressed this in versions 26.3 and 25.6.6.

Affected products

  • Adobe Media Encoder <= 26.2.2, <= 25.6.5

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats