CVE-2026-34641
Adobe Premiere Pro vulnerability analysis and mitigation

Overview

CVE-2026-34641 is an out-of-bounds write vulnerability (stack-based buffer overflow) in Adobe Premiere Pro that could allow arbitrary code execution in the context of the current user. It affects Adobe Premiere Pro versions up to and including 25.6.5 (fixed in 25.6.6) and Premiere versions up to and including 26.2.2 (fixed in 26.3). The vulnerability was first disclosed by Adobe on May 12, 2026, and formally published to NVD on July 31, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write) and CWE-121 (Stack-based Buffer Overflow), meaning the application writes data beyond the bounds of an allocated stack buffer during file parsing. An attacker exploits this by crafting a malicious media or project file that, when opened by a victim in Premiere Pro, triggers the out-of-bounds write condition. The attack vector is local, requires no privileges, but does require user interaction — specifically, a victim must open the malicious file. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation results in arbitrary code execution in the context of the current user, yielding high impact to confidentiality, integrity, and availability. An attacker could read sensitive files accessible to the user, modify or destroy data, or cause the application to crash. Because the exploit runs with the victim's privileges, lateral movement potential is limited to the user's access scope, though it could serve as an initial foothold for further attacks (Adobe Advisory, GitHub Advisory).

Exploitability

There is no known in-the-wild exploitation of CVE-2026-34641 as of the available data, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not automatable due to the required user interaction. The EPSS score is approximately 0.139%, placing it in the 4th percentile for exploitation likelihood within 30 days (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted media or project file (e.g., a video project file or supported media format) designed to trigger the stack-based buffer overflow when parsed by Adobe Premiere Pro.
  2. Deliver the file to the victim: The attacker distributes the malicious file via phishing email, file-sharing platforms, or social engineering, targeting users who work with Premiere Pro.
  3. Victim opens the file: The victim opens the malicious file in a vulnerable version of Adobe Premiere Pro (≤25.6.5 or ≤26.2.2), triggering the out-of-bounds write during file parsing.
  4. Achieve code execution: The memory corruption caused by the out-of-bounds write is leveraged to redirect execution flow, resulting in arbitrary code execution in the context of the current user's account (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by Adobe Premiere Pro (e.g., cmd.exe, powershell.exe, bash, curl, or other shells/utilities) following the opening of a media or project file.
  • File System: Presence of unknown or unexpected files written to user-accessible directories shortly after Premiere Pro opens a file; new executables or scripts in temp directories.
  • Logs: Application crash logs or Windows Error Reporting entries referencing Premiere Pro with memory access violations or stack corruption indicators.
  • Network: Unusual outbound network connections originating from the Premiere Pro process to unknown external IP addresses or domains following file open events.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Premiere Pro 25.6.6 and Premiere 26.3. Users should update to these versions or later via the Creative Cloud desktop application. No configuration-based workarounds have been published; upgrading is the recommended and only confirmed remediation (Adobe Advisory). As a general precaution, users should avoid opening Premiere Pro project or media files from untrusted or unknown sources.

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products could allow for arbitrary code execution, referencing this CVE among others patched in Adobe's May 2026 update cycle (CIS Advisory). CISA also referenced the vulnerability in its weekly bulletin. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage.

Additional resources


SourceThis report was generated using AI

Related Adobe Premiere Pro vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34641HIGH7.8
  • Adobe Premiere Pro logoAdobe Premiere Pro
  • cpe:2.3:a:adobe:premiere_pro
NoYesJul 31, 2026
CVE-2026-48369HIGH7.8
  • Adobe Premiere Pro logoAdobe Premiere Pro
  • cpe:2.3:a:adobe:premiere_pro
NoNoJul 14, 2026
CVE-2026-48270HIGH7.8
  • Adobe Premiere Pro logoAdobe Premiere Pro
  • cpe:2.3:a:adobe:premiere_pro
NoNoJul 14, 2026
CVE-2026-48269HIGH7.8
  • Adobe Premiere Pro logoAdobe Premiere Pro
  • cpe:2.3:a:adobe:premiere_pro
NoNoJul 14, 2026
CVE-2026-48308MEDIUM5.9
  • Adobe Premiere Pro logoAdobe Premiere Pro
  • cpe:2.3:a:adobe:premiere_pro
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management