Description
After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe After Effects is affected by an out‑of‑bounds write that can lead to arbitrary code execution in the context of the user who opens a malicious file. The flaw is classified as CWE‑787 and allows an attacker to corrupt memory on the stack or heap. The vulnerability is triggered by opening a specially crafted file; no network or elevated privileges are required. Successful exploitation could give the attacker full control over the process, potentially enabling further lateral movement or persistence within the victim’s workload. The CVSS score of 7.8 reflects a high severity impact. The EPSS score of < 1 % indicates a low probability of widespread exploitation, and the vulnerability is not present in the CISA KEV catalog. Because a victim must voluntarily open a malicious file, user awareness and proper file handling remain the primary defense.

Affected Systems

Adobe After Effects is the affected product. No specific version ranges are disclosed by Adobe; the advisory states that the flaw exists in the current releases available at the time of publication.

Risk and Exploitability

A score of 7.8 indicates a high‑severity flaw, but the extremely low EPSS implies that widespread attacks are unlikely at present. No listing in the KEV catalog further reduces the threat pulse. The attack vector requires user interaction to open a malicious file, making social engineering and user education key mitigations.

Generated by OpenCVE AI on July 31, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe PSB 26‑78 patch for After Effects.
  • Configure the application to strictly allow only trusted file types and block any unknown or suspicious inputs.
  • Train end‑users to verify the origin of any file before opening it within After Effects and to avoid untrusted files.

Generated by OpenCVE AI on July 31, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe after Effects
Vendors & Products Adobe
Adobe after Effects

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title After Effects | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe After Effects
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:40:23.783Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48367

cve-icon Vulnrichment

Updated: 2026-07-15T10:40:18.692Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses