Description
After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-05-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

After Effects contains a stack‑buffer overflow that can lead to arbitrary code execution in the current user’s context when a crafted file is opened. The flaw is triggered by user interaction—specifically opening a malicious file; once triggered, the attacker can run code with the victim’s privileges, potentially compromising the application and, if the code executes with elevated permissions, the operating system.

Affected Systems

Adobe After Effects is the affected product. Versions of the application that are installed on macOS and Windows operating systems are vulnerable. All releases of After Effects that do not include the vendor’s update for this issue are at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies this vulnerability as high severity. The EPSS score of < 1% indicates that the likelihood of exploitation is very low at present, but the requirement for user interaction—opening a malicious file—reduces the probability of automated attacks. The vulnerability is not listed in the CISA KEV catalog, yet the potential for arbitrary code execution warrants close attention.

Generated by OpenCVE AI on July 26, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe After Effects update that fixes the stack‑based buffer overflow (refer to the Adobe APSB26‑48 advisory).
  • Ensure that the installed After Effects version is at least the latest release that contains the fix.
  • Implement user training and restrict opening of unfamiliar or unsigned files; consider scanning files with antivirus before they are opened in After Effects.

Generated by OpenCVE AI on July 26, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description After Effects versions 26.0, 25.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
References

Thu, 14 May 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Microsoft
Microsoft windows

Tue, 12 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe after Effects
Vendors & Products Adobe
Adobe after Effects

Tue, 12 May 2026 20:15:00 +0000

Type Values Removed Values Added
Description After Effects versions 26.0, 25.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title After Effects | Stack-based Buffer Overflow (CWE-121)
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe After Effects
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T21:29:40.530Z

Reserved: 2026-03-30T17:30:36.496Z

Link: CVE-2026-34690

cve-icon Vulnrichment

Updated: 2026-05-13T13:16:52.011Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T20:16:38.820

Modified: 2026-06-17T10:39:27.043

Link: CVE-2026-34690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T00:30:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow