
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34690 is a Stack-based Buffer Overflow vulnerability (CWE-121) in Adobe After Effects that could allow arbitrary code execution in the context of the current user. It affects After Effects versions 26.0 and 25.6.4 and earlier, with fixed versions released on May 12, 2026. The vulnerability was published on May 12, 2026, and a patch was made available the same day via Adobe's security advisory APSB26-48. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), where insufficient bounds checking during file parsing allows a specially crafted file to overflow a stack buffer. An attacker exploits this by crafting a malicious project or media file and convincing a victim to open it in After Effects, triggering the overflow and enabling arbitrary code execution. The attack vector is local (the malicious file must be opened by the user), requires no privileges, but does require user interaction. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe After Effects, resulting in high confidentiality, integrity, and availability impact within the user's security context. An attacker could read sensitive files, modify or delete data, or install malware on the affected system. The scope is limited to the current user's context, but on systems where After Effects users have elevated privileges, the impact could be more severe (Adobe Advisory, GitHub Advisory).
.aep) or supported media file that triggers the stack-based buffer overflow during parsing.Adobe has released patched versions addressing this vulnerability: After Effects 25.6.5 (for users on the 25.x branch) and 26.2 (for users on the 26.x branch). Users should update immediately via the Creative Cloud desktop application. As a general workaround, users should avoid opening After Effects project files or media files received from untrusted or unknown sources. Organizations should consider restricting After Effects access to trusted users and enabling application allowlisting where feasible (Adobe Advisory).
The vulnerability was noted in Fortress SRM's May 2026 threat and security update roundup, indicating it was included in broader patch Tuesday coverage. Detection support was added by Qualys (detection ID 387309) and Tenable (Nessus plugin 314329) shortly after disclosure. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking (Adobe Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."