Description
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Premiere Pro suffers from an out-of-bounds write that enables arbitrary code execution when a malicious file is opened. The vulnerability is a CWE‑787 memory safety flaw that can overwrite critical memory structures, potentially allowing an attacker to run arbitrary code as the current logged‑in user if they successfully trigger the write. Because the vulnerability requires the user to open a crafted media file, exploitation is limited to scenarios where the victim opens the file.

Affected Systems

Adobe’s Premiere Pro is the impacted product. Specific affected versions are not listed in the advisory, so all installations of Premiere Pro should assume exposure until a patch status update is published.

Risk and Exploitability

The CVSS score of 7.8 marks it as a high‑severity flaw, yet the EPSS score of less than 1% indicates a very low exploitation probability under current threat landscape. It is not catalogued in CISA’s KEV list, further suggesting limited active exploitation. Attackers would need to deliver a malicious file that the user opens, so remote exploitation without user interaction is not viable. In environments where untrusted media is commonly opened, the risk of privilege escalation and compromise is significant.

Generated by OpenCVE AI on July 31, 2026 at 05:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe’s latest security update for Premiere Pro that fixes the out-of-bounds write.
  • Disable automatic media preview or file auto‑open features in Premiere Pro until the update is installed.
  • Use endpoint protection and file‑integrity monitoring to detect and block suspicious media files before they are opened.

Generated by OpenCVE AI on July 31, 2026 at 05:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe premiere
Vendors & Products Adobe
Adobe premiere

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Premiere Pro | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:37:51.242Z

Reserved: 2026-05-21T15:28:38.132Z

Link: CVE-2026-48270

cve-icon Vulnrichment

Updated: 2026-07-15T10:37:46.118Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses