Description
After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds write that allows an attacker to overwrite memory and execute arbitrary code while running in the user’s context. This can compromise confidentiality, integrity, and availability of the affected system by allowing a malicious user to run arbitrary programs, steal data, or disrupt operations. The weakness is classified as CWE-787. No specific product versions are listed, so the vulnerability is presumed to impact all releases of the software.

Affected Systems

Affected systems include Adobe After Effects for all versions in use at the time of the advisory. The advisory lists no specific version constraints; therefore the vulnerability applies to every release of After Effects that was available when Adobe issued APSB26‑78.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity with the potential for remote code execution. The EPSS score of less than 1% suggests that the probability is very low at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a malicious file, implying that a social‑engineering or phishing file into After Effects.

Generated by OpenCVE AI on July 31, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe After Effects update released in the Adobe Security Bulletin APSB26-78
  • Restrict the ability to open unsolicited or unknown file types within After Effects and untrusted locations
  • Educate users to avoid opening unknown or suspicious files that may be malicious and verify source credibility before loading Adobe media or project files

Generated by OpenCVE AI on July 31, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe after Effects
Vendors & Products Adobe
Adobe after Effects

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title After Effects | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe After Effects
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:40:37.459Z

Reserved: 2026-05-21T15:28:38.133Z

Link: CVE-2026-48274

cve-icon Vulnrichment

Updated: 2026-07-15T10:40:32.294Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses