Junglewise Threat Intelligence

CVE-2026-76191: Adobe Animate code injection vulnerability

CVE-2026-76191 · Severity: high · CVSS 8.2 · Published 2026-09-08

Executive brief

Adobe Animate, a tool for creating interactive animations and multimedia content, is vulnerable to code injection through specially crafted files. An attacker could trick a user into opening a malicious file to execute arbitrary code with the user's privileges, potentially compromising sensitive projects and system access.

Technical details

The vulnerability is a code injection flaw in Adobe Animate's file handling that allows improper control of code generation. An attacker can craft a malicious file that, when opened by a victim in Animate, injects and executes arbitrary code in the context of the current user. This requires user interaction (opening a file) and results in a change of scope. No authentication is required beyond the user's ability to open the file locally. Patches are expected from Adobe; refer to APSB26-132 for update guidance.

Affected products

  • Adobe Animate <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats