
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21350 is a NULL Pointer Dereference vulnerability (CWE-476) in Adobe After Effects that can result in application denial-of-service and, under certain conditions, arbitrary code execution. It affects Adobe After Effects versions prior to 25.6.4 and was disclosed on February 10, 2026, with a patch released the same day. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) for the denial-of-service impact, though the broader advisory context rates the arbitrary code execution impact as Critical (Adobe Advisory, Feedly).
The root cause is a NULL Pointer Dereference (CWE-476) in Adobe After Effects, triggered when the application processes a specially crafted file. The attack vector is local, requiring low attack complexity and no privileges, but does require user interaction — specifically, a victim must open a malicious file. An attacker could leverage social engineering to deliver the crafted file, causing the application to dereference a null pointer, leading to a crash (denial-of-service) or potentially arbitrary code execution with the privileges of the After Effects process (Adobe Advisory, Feedly).
Successful exploitation can cause application denial-of-service (crash) or arbitrary code execution with the privileges of the Adobe After Effects process. Since the attack is local and requires user interaction, the primary risk involves social engineering scenarios where a victim opens a malicious project or media file. There is no impact on confidentiality or integrity in the denial-of-service scenario, but arbitrary code execution could allow an attacker to access sensitive data or perform unauthorized actions on the affected system (Adobe Advisory, Feedly).
AfterFX.exe on Windows) after opening an untrusted file.AfterFX.exe with access violation or null pointer exception errors..aep, .aepx) or media files received from unknown sources in user directories.Adobe has released a patch in Adobe After Effects version 25.6.4, which resolves this vulnerability. Users should update to version 25.6.4 or later immediately via the Creative Cloud desktop application. As a precautionary measure, users should avoid opening After Effects project files or media files from untrusted or unknown sources. Organizations may also consider implementing application whitelisting and restricting execution of untrusted files (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Beyond Machines also covered Adobe's February 2026 patch release, highlighting the breadth of fixes across multiple Adobe products. No significant independent researcher commentary or social media discussion has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."