
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48367 is an out-of-bounds write vulnerability (CWE-787) in Adobe After Effects that could result in arbitrary code execution in the context of the current user. It affects Adobe After Effects versions 25.6.5 and earlier, and versions 26.0 through 26.2.1, on both Windows and macOS. Adobe disclosed and patched the vulnerability on July 14, 2026, as part of its July 2026 security update cycle. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during file parsing or processing. Exploitation requires a local attack vector with no privileges required, but does require user interaction — specifically, a victim must open a specially crafted malicious file in After Effects. The flaw likely resides in the application's media or project file parsing logic, where insufficient bounds checking allows an attacker-controlled value to overwrite adjacent memory, potentially redirecting code execution. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who tricks a user into opening a malicious After Effects project or media file could gain full control of the user's session, access sensitive data, install malware, or pivot to other systems accessible from the compromised account. The scope is limited to the affected host and user context, with no automatic privilege escalation beyond the current user's permissions (Adobe Advisory, GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit for CVE-2026-48367 at this time. The EPSS score is approximately 0.149%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable due to the required user interaction (Adobe Advisory, GitHub Advisory).
.aep) or supported media file that contains malformed data designed to trigger an out-of-bounds write during parsing..aep or media files received via email or downloaded from untrusted sources; new executable files or scripts created in user-writable directories (e.g., %APPDATA%, /tmp) shortly after opening an After Effects file.cmd.exe, powershell.exe, bash, curl, wget); After Effects process making unexpected outbound network connections.Adobe has released patched versions addressing this vulnerability: users on the 25.x branch should update to version 25.6.6 or later, and users on the 26.x branch should update to version 26.3 or later. Updates are available through the Adobe Creative Cloud desktop application. As an interim workaround until patching is possible, users should avoid opening After Effects project files or media files received from untrusted or unknown sources. Organizations should also consider restricting After Effects usage to trusted file sources via endpoint controls (Adobe Advisory).
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Tenable published detection plugins for the vulnerability shortly after disclosure. No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability aggregation and advisory coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."