Description
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw in Adobe Media Encoder allows an attacker to overwrite adjacent memory when the program processes a specially crafted file, potentially leading to arbitrary code execution in the context of the user who opens that file. This vulnerability is classified as CWE‑787 and presents a risk that an attacker who can embed a malicious media file within an email or other file exchange mechanism can gain control of the system on the victim’s machine.

Affected Systems

Adobe Media Encoder is impacted; vendor and product information is confirmed, but specific affected version numbers are not provided in the available data.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity for a local user interaction scenario. An EPSS score of less than 1% suggests that exploitation is rarely observed. The vulnerability is not in the CISA KEV catalog. Exploitation requires that a user opens a malicious file, so the likely vector is a file distributed via email, download, or other media sharing channels. Because the code executes with the user’s privileges, a successful exploit would allow an attacker to run arbitrary code, modify data, or further compromise the system.

Generated by OpenCVE AI on July 31, 2026 at 05:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Adobe Media Encoder security update referenced in Adobe’s Security Bulletin APSB26-72.
  • Implement controls to scan or quarantine media files before they can be opened, such as configuring email safe attachment handling or using application whitelisting for Media Encoder.
  • Conduct user awareness training to advise staff to avoid opening files from unknown or untrusted sources and to verify the integrity of media files received.

Generated by OpenCVE AI on July 31, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe media Encoder
Vendors & Products Adobe
Adobe media Encoder

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Media Encoder | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Media Encoder
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:36:17.340Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48370

cve-icon Vulnrichment

Updated: 2026-07-15T10:36:12.247Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses