
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34641 is an out-of-bounds write vulnerability (stack-based buffer overflow) in Adobe Premiere Pro that could allow arbitrary code execution in the context of the current user. It affects Adobe Premiere Pro versions up to and including 25.6.5 (fixed in 25.6.6) and Premiere versions up to and including 26.2.2 (fixed in 26.3). The vulnerability was first disclosed by Adobe on May 12, 2026, and formally published to NVD on July 31, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write) and CWE-121 (Stack-based Buffer Overflow), meaning the application writes data beyond the bounds of an allocated stack buffer during file parsing. An attacker exploits this by crafting a malicious media or project file that, when opened by a victim in Premiere Pro, triggers the out-of-bounds write condition. The attack vector is local, requires no privileges, but does require user interaction — specifically, a victim must open the malicious file. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation results in arbitrary code execution in the context of the current user, yielding high impact to confidentiality, integrity, and availability. An attacker could read sensitive files accessible to the user, modify or destroy data, or cause the application to crash. Because the exploit runs with the victim's privileges, lateral movement potential is limited to the user's access scope, though it could serve as an initial foothold for further attacks (Adobe Advisory, GitHub Advisory).
There is no known in-the-wild exploitation of CVE-2026-34641 as of the available data, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not automatable due to the required user interaction. The EPSS score is approximately 0.139%, placing it in the 4th percentile for exploitation likelihood within 30 days (GitHub Advisory, Adobe Advisory).
cmd.exe, powershell.exe, bash, curl, or other shells/utilities) following the opening of a media or project file.Adobe has released patched versions addressing this vulnerability: Premiere Pro 25.6.6 and Premiere 26.3. Users should update to these versions or later via the Creative Cloud desktop application. No configuration-based workarounds have been published; upgrading is the recommended and only confirmed remediation (Adobe Advisory). As a general precaution, users should avoid opening Premiere Pro project or media files from untrusted or unknown sources.
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products could allow for arbitrary code execution, referencing this CVE among others patched in Adobe's May 2026 update cycle (CIS Advisory). CISA also referenced the vulnerability in its weekly bulletin. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."