CVE-2026-21321: After Effects | Integer Overflow or Wraparound (CWE-190)
Published Feb 10, 2026
·Updated
After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe After Effects<=25.6
All of the following
Adobe After Effects<25.6.4
Any of the following
Apple macOS
Microsoft Windows
Event History
Feb 10, 2026
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21321?
The severity of CVE-2026-21321 is high due to the potential for arbitrary code execution.
2
How do I fix CVE-2026-21321?
To fix CVE-2026-21321, users should update Adobe After Effects to the latest version beyond 25.6.
3
Which versions of Adobe After Effects are affected by CVE-2026-21321?
Adobe After Effects versions 25.6 and earlier are affected by CVE-2026-21321.
4
What are the consequences of exploiting CVE-2026-21321?
Exploitation of CVE-2026-21321 could lead to arbitrary code execution in the context of the current user.
5
What is the nature of the vulnerability described in CVE-2026-21321?
CVE-2026-21321 is an Integer Overflow or Wraparound vulnerability.