Out-of-Bounds Write Vulnerability in Adobe After Effects
CVE-2026-34643

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34643?

Adobe After Effects contains an out-of-bounds write vulnerability affecting versions 26.0, 25.6.4, and earlier. This flaw allows attackers to potentially execute arbitrary code within the context of the current user, but it necessitates user interaction—specifically, the victim must open a specially crafted file designed to trigger this vulnerability. Mitigation efforts are critical to prevent exploitation.

Affected Version(s)

After Effects 0 <= 25.6.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.