Junglewise Threat Intelligence

CVE-2026-48370: Adobe Media Encoder out-of-bounds write

CVE-2026-48370 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Adobe Media Encoder. Vendors: Adobe.

Executive brief

Adobe Media Encoder, a professional application used for processing and converting video files, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious media file. If successful, the attacker could run unauthorized software or access sensitive data with the same permissions as the logged-in user.

Technical details

Adobe Media Encoder is vulnerable to an out-of-bounds write (CWE-787) when processing specially crafted files. The vulnerability occurs because the application does not properly validate the boundaries of a memory buffer before writing data to it. An attacker can exploit this by providing a malicious file that, when opened by a user, triggers memory corruption. This can lead to arbitrary code execution within the security context of the current user. The attack requires local access to deliver the file and relies on user interaction (UI:R). Adobe has released patches in versions 25.6.6 and 26.3 to address this issue.

Affected products

  • Adobe Media Encoder <= 25.6.5, <= 26.2.2

Timeline

  • 2026-07-14: advisory: Adobe published the security bulletin APSB26-72
  • 2026-07-14: disclosed: CVE-2026-48370 published to the NVD dataset

References

Related threats