CVE-2026-21322: After Effects | Out-of-bounds Read (CWE-125)
After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21322?
CVE-2026-21322 is considered a significant vulnerability due to its potential for enabling out-of-bounds read attacks in Adobe After Effects.
How do I fix CVE-2026-21322?
To fix CVE-2026-21322, update Adobe After Effects to version 25.7 or later, which addresses the vulnerability.
What versions of Adobe After Effects are affected by CVE-2026-21322?
Adobe After Effects versions 25.6 and earlier are affected by CVE-2026-21322.
What could an attacker achieve by exploiting CVE-2026-21322?
An attacker could potentially execute arbitrary code by exploiting CVE-2026-21322 through crafted file parsing.
Is CVE-2026-21322 a vulnerability for macOS and Windows?
CVE-2026-21322 specifically impacts Adobe After Effects, and it is not a vulnerability on macOS or Windows operating systems themselves.