CVE-2026-34643: After Effects | Out-of-bounds Write (CWE-787)
Published May 12, 2026
·Updated
After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
Adobe After Effects<=25.6.4, =26.0
Adobe After Effects<25.6.5
Adobe After Effects=26.0
Event History
May 12, 2026
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34643?
CVE-2026-34643 has a critical severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-34643?
To mitigate CVE-2026-34643, update Adobe After Effects to version 26.0.1 or later.
3
What versions of Adobe After Effects are affected by CVE-2026-34643?
Adobe After Effects versions 26.0 and 25.6.4 and earlier are affected by CVE-2026-34643.
4
What can be the impact of exploiting CVE-2026-34643?
Exploiting CVE-2026-34643 can allow an attacker to execute arbitrary code in the context of the current user.
5
Does exploiting CVE-2026-34643 require user interaction?
Yes, exploitation of CVE-2026-34643 requires user interaction to trigger the vulnerability.