Description
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Premiere Pro suffers from an out‑of‑bounds write that permits an attacker to run arbitrary code within the privileges of the user who opens a malicious file. The flaw is a classic buffer overflow (CWE‑787) and could affect confidentiality, integrity, or availability of the victim’s data if exploited.

Affected Systems

Adobe Premiere Pro, with no specific vulnerable versions listed in the CVE. The Adobe Security Bulletin APSB26‑76 contains the remediation; users should verify their version and apply the patch.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity impact. An EPSS score of less than 1 % suggests that exploitation is currently considered rare. Because the flaw requires user interaction—an attacker must supply and the victim must open a malicious file—the attack vector is via social engineering or compromised media. The vulnerability is not listed in the CISA KEV catalog. Once the Adobe update is applied, the risk is effectively eliminated.

Generated by OpenCVE AI on July 31, 2026 at 05:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Premiere Pro update referenced in APSB26‑76 to fix the out‑of‑bounds write flaw.
  • If a patch is not yet available, restrict or disable opening of unknown or untrusted files in Premiere Pro until the update is installed.
  • Monitor system and application logs for anomalous activity that might indicate an attempted or successful exploitation.

Generated by OpenCVE AI on July 31, 2026 at 05:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe premiere
Vendors & Products Adobe
Adobe premiere

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Premiere Pro | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:37:37.619Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48369

cve-icon Vulnrichment

Updated: 2026-07-15T10:37:33.067Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses