Description
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overrun in Adobe Media Encoder allows a specially crafted file to cause an out‑of‑bounds write, which can be exploited to execute arbitrary code in the context of the user who opens the file. The flaw is triggered when the program parses the malicious file, following the vulnerability description that the impact is execution of malicious code with the victim’s permissions.

Affected Systems

The vulnerability affects all installations of Adobe Media Encoder that have not applied the latest security patch. No precise version ranges are provided, so any copy of the software prior to the vendor’s corrective update is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, yet the EPSS score of less than 1% suggests that real‑world exploitation is uncommon at this time. The issue is not listed in CISA’s KEV catalog. Because an attacker must convince a user to open a malicious file, likely vectors include phishing, social engineering, or drive‑by delivery. The combination of high impact with low exploitation probability still warrants timely remediation.

Generated by OpenCVE AI on July 31, 2026 at 05:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Adobe Media Encoder that corrects the out‑of‑bounds write flaw, as detailed in the Adobe advisory.
  • Configure file‑type restrictions or sandboxing so that untrusted Media Encoder files cannot execute code automatically when opened by a user.
  • Deploy endpoint protection that scans for known malicious Media Encoder signatures and blocks them before the user can open the file.

Generated by OpenCVE AI on July 31, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe media Encoder
Vendors & Products Adobe
Adobe media Encoder

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Media Encoder | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Media Encoder
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:36:03.752Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48366

cve-icon Vulnrichment

Updated: 2026-07-15T10:35:58.609Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:03Z

Weaknesses