Adobe Vulnerabilities and Affected Products
Vulnerabilities associated with After Effects.
Products
Clear product- Adobe Experience Manager1,018 vulnerabilities
- Adobe Acrobat and Reader516 vulnerabilities
- Acrobat Reader447 vulnerabilities
- Adobe Commerce190 vulnerabilities
- ColdFusion149 vulnerabilities
- Illustrator149 vulnerabilities
- InDesign Desktop131 vulnerabilities
- After Effects119 vulnerabilities
- Dimension116 vulnerabilities
- Bridge114 vulnerabilities
- Animate101 vulnerabilities
- Experience Manager98 vulnerabilities
- InDesign96 vulnerabilities
- Substance3D - Stager87 vulnerabilities
- Magento Commerce85 vulnerabilities
- Adobe Framemaker82 vulnerabilities
- experience_manager78 vulnerabilities
- Substance3D - Painter78 vulnerabilities
- Flash Player70 vulnerabilities
- InCopy65 vulnerabilities
- Photoshop58 vulnerabilities
- experience_manager_cloud_service53 vulnerabilities
- acrobat_reader49 vulnerabilities
- FrameMaker48 vulnerabilities
- acrobat_reader_dc47 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-48367HIGH | After Effects | Out-of-bounds Write (CWE-787)After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Jul 14, 2026 | CVSS7.8v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-48274HIGH | After Effects | Out-of-bounds Write (CWE-787)After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Jul 14, 2026 | CVSS7.8v3.1 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-34690HIGH | After Effects | Stack-based Buffer Overflow (CWE-121)After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-121May 12, 2026 | CVSS7.8v3.1 | EPSS0.347% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-34644HIGH | After Effects | Integer Overflow or Wraparound (CWE-190)After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-190May 12, 2026 | CVSS7.8v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-34643HIGH | After Effects | Out-of-bounds Write (CWE-787)After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787May 12, 2026 | CVSS7.8v3.1 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-34642HIGH | After Effects | Heap-based Buffer Overflow (CWE-122)After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-122May 12, 2026 | CVSS7.8v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21329HIGH | After Effects | Use After Free (CWE-416)After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21323HIGH | After Effects | Use After Free (CWE-416)After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21324HIGH | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21326HIGH | After Effects | Use After Free (CWE-416)After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21322HIGH | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21318HIGH | After Effects | Out-of-bounds Write (CWE-787)After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21328HIGH | After Effects | Out-of-bounds Write (CWE-787)After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21319MEDIUM | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 10, 2026 | CVSS5.5v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21350MEDIUM | After Effects | NULL Pointer Dereference (CWE-476)After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-476Feb 10, 2026 | CVSS5.5v3.1 | EPSS0.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21330HIGH | After Effects | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-843Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21325HIGH | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21327HIGH | After Effects | Out-of-bounds Write (CWE-787)After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21320HIGH | After Effects | Use After Free (CWE-416)After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21321HIGH | After Effects | Integer Overflow or Wraparound (CWE-190)After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-190Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21351HIGH | After Effects | Use After Free (CWE-416)After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Feb 10, 2026 | CVSS7.8v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-54241MEDIUM | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Sep 9, 2025 | CVSS5.5v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-54239MEDIUM | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Sep 9, 2025 | CVSS5.5v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-54240MEDIUM | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Sep 9, 2025 | CVSS5.5v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43587MEDIUM | After Effects | Out-of-bounds Read (CWE-125)After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Jul 8, 2025 | CVSS5.5v3.1 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |