
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48365 is an out-of-bounds write vulnerability in Adobe Audition that can result in arbitrary code execution in the context of the current user. Disclosed on July 14, 2026, as part of Adobe's July 2026 security update cycle, it affects Adobe Audition versions 25.6.4 and earlier (fixed in 25.6.6) and versions 26.0 and earlier (fixed in 26.3) on both Windows and macOS. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by Adobe Systems Incorporated (Adobe Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the bounds of an allocated memory buffer during the processing of a malicious audio file. The attack vector is local (AV:L), requiring no special privileges but necessitating user interaction — specifically, a victim must open a crafted malicious file. No public technical write-ups or proof-of-concept code detailing the precise file format or parsing component involved have been identified at this time (Adobe Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe Audition, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access sensitive files, install malware, or use the compromised host as a pivot point for lateral movement within a network. The scope is limited to the current user context, but in environments where Audition is run with elevated privileges, the blast radius could be significantly larger (Adobe Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-48365 at this time. CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the requirement for user interaction. The EPSS score is approximately 0.0018 (0.18%), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog (Adobe Advisory, CIS Advisory).
cmd.exe, powershell.exe, bash, curl, wget) that are not expected during normal audio editing workflows.Adobe Audition.exe or AdobeAudition) to external IP addresses or domains.Adobe has released patched versions addressing this vulnerability: Adobe Audition 25.6.6 (for the 25.x branch) and Adobe Audition 26.3 (for the 26.x branch) on both Windows and macOS. Users should update immediately via the Creative Cloud desktop application or Adobe's official download channels. As interim mitigations, users should avoid opening audio files from untrusted or unknown sources, and administrators should consider implementing endpoint protection controls to monitor for suspicious process execution originating from Audition (Adobe Advisory, CIS Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). CISA included the vulnerability in its weekly bulletin (SB26-201), reflecting standard tracking of Adobe's July 2026 patch cycle. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond routine vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."