Executive brief
Adobe Animate, a tool for creating interactive animations and multimedia content, is vulnerable to code injection through specially crafted files. An attacker could trick a user into opening a malicious file to execute arbitrary code with the user's privileges, potentially compromising sensitive projects and system access.
Technical details
The vulnerability is a code injection flaw in Adobe Animate's file handling that allows improper control of code generation. An attacker can craft a malicious file that, when opened by a victim in Animate, injects and executes arbitrary code in the context of the current user. This requires user interaction (opening a file) and results in a change of scope. No authentication is required beyond the user's ability to open the file locally. Patches are expected from Adobe; refer to APSB26-132 for update guidance.
Affected products
- Adobe Animate <UNKNOWN>
Timeline
- 2026-09-08: disclosed