Description
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Media Encoder contains an out‑of‑bounds write that can be triggered when the program parses a specially crafted media file, resulting in a buffer overflow. An attacker who supplies such a file can cause the application to execute arbitrary code in the context of the user who opens it, potentially compromising the confidentiality, integrity, and availability of the system.

Affected Systems

Adobe Media Encoder is the affected product. All releases without the fix detailed in Adobe Security Bulletin APSb26‑72 are likely vulnerable; no specific version numbers are provided. The advisory does not list any particular releases that are unaffected.

Risk and Exploitability

The CVSS score of 7.8 places this vulnerability in the medium‑high severity range. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalogue. Exploitation requires the victim to open a malicious media file, so the attack vector is user interaction. Attackers would need to deliver the file via phishing, social engineering, or compromised media sharing channels.

Generated by OpenCVE AI on July 31, 2026 at 05:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update for Adobe Media Encoder published in bulletin APSb26‑72.
  • If the update is not yet available, configure Media Encoder to reject or quarantine unknown media files before opening, and/or run the application in a sandbox environment.
  • Disable automatic opening or drag‑and‑drop of media files in the application to reduce the risk of accidental execution.

Generated by OpenCVE AI on July 31, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe media Encoder
Vendors & Products Adobe
Adobe media Encoder

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Media Encoder | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Media Encoder
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:36:30.397Z

Reserved: 2026-05-20T15:50:31.365Z

Link: CVE-2026-47976

cve-icon Vulnrichment

Updated: 2026-07-15T10:36:25.800Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:03Z

Weaknesses