
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34643 is an out-of-bounds write vulnerability in Adobe After Effects that could result in arbitrary code execution in the context of the current user. It affects After Effects versions 26.0, 25.6.4, and earlier (all versions prior to 25.6.5 in the 25.x branch). Adobe disclosed and patched this vulnerability on May 12, 2026, via security advisory APSB26-48. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the bounds of an allocated memory buffer during file parsing. Exploitation requires a local attack vector and user interaction — specifically, a victim must open a specially crafted malicious file in After Effects. No privileges are required by the attacker, and the attack complexity is low, making it straightforward to exploit once a victim is socially engineered into opening the malicious file (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Adobe After Effects, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files, modify or destroy data, or install malware on the victim's machine. The scope is limited to the current user's context, but could facilitate further lateral movement if the user has elevated privileges (Adobe Advisory).
.aep) designed to trigger an out-of-bounds write during file parsing..aep (After Effects project) files received via email or downloaded from untrusted sources; new or modified executables/scripts in user-writable directories following After Effects file open events.cmd.exe, powershell.exe, curl, wget) shortly after opening a project file.Adobe has released patched versions addressing this vulnerability: After Effects 25.6.5 (for the 25.x branch) and After Effects 26.1 or later (for the 26.x branch). Users should update immediately via the Creative Cloud desktop application. As a temporary workaround until patching is possible, organizations should restrict users from opening After Effects project files received from untrusted or external sources (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching. Coverage was also noted from security aggregators and threat intelligence platforms shortly after Adobe's May 12, 2026 disclosure (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."