
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21319 is an Out-of-bounds Read vulnerability (CWE-125) in Adobe After Effects that can lead to memory exposure. It affects Adobe After Effects versions 25.6 and earlier (all versions prior to 25.6.4). Adobe disclosed and patched this vulnerability on February 10, 2026, as part of its February 2026 security update cycle. It carries a CVSS v3.1 base score of 5.5 (Medium), with a confidentiality impact only — no integrity or availability impact (Adobe Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), meaning the application reads data beyond the allocated memory buffer when processing a specially crafted file. Exploitation requires local access and user interaction — specifically, a victim must open a malicious file in Adobe After Effects. No elevated privileges are required for the attacker to deliver the malicious file. The attack vector is local, and the flaw enables an attacker to read sensitive data from the application's memory space (Adobe Advisory, Feedly).
Successful exploitation allows an attacker to access and extract sensitive information stored in Adobe After Effects' memory space, resulting in unauthorized disclosure of confidential data. There is no impact on system integrity or availability — the vulnerability is limited to a confidentiality breach. The scope of impact is confined to the affected application's memory and does not directly enable lateral movement or code execution (Adobe Advisory).
.aep) or media files received via email or downloaded from untrusted sources.AfterFX.exe) crashing or exhibiting abnormal behavior when opening specific files.Adobe has released a patch in After Effects version 25.6.4, which addresses this vulnerability. Organizations should upgrade all installations of Adobe After Effects to version 25.6.4 or later immediately. As a precautionary measure, users should avoid opening After Effects files from untrusted or unknown sources. Restricting the ability to open After Effects files from external sources (e.g., via email filtering or endpoint controls) can reduce exposure until patching is complete (Adobe Advisory, CIS Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Tenable flagged the vulnerability in its plugin pipeline shortly after disclosure. Overall community reaction has been muted given the medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."