Use After Free Vulnerability in After Effects by Adobe
CVE-2026-21351

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 February 2026

What is CVE-2026-21351?

A Use After Free vulnerability in Adobe After Effects versions 25.6 and earlier allows an attacker to execute arbitrary code in the context of the current user. Exploitation of this vulnerability necessitates user interaction; the victim must open a specially crafted malicious file for the attack to succeed. This can pose serious security risks if users inadvertently open compromised content.

Affected Version(s)

After Effects 0 <= 25.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.