CVE-2026-21319Disclosure(adobe / after_effects)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch adobe after_effects systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • after_effects
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-12)
  • 3 total mentions across 2 days

Affected systems

Products
after_effectsmacoswindows

1 version affected across 3 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-10: 1Mentions · 2026-02-12: 2Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 202-1002-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-122
Disclosure1Patch1
Full discourse3 posts
  • transilienceai@transilienceai
    Disclosure

    @decernly ⚠️ CVE-2026-21319 specifically enables attackers to read sensitive memory beyond buffer boundaries via crafted files. No known exploits exist in the wild, but risks are heightened for users handling untrusted content from email or file sharing. #Vulnerability

    Post summary

    The post highlights CVE-2026-21319, a buffer overflow that allows reading sensitive memory via crafted files, noting that no exploits have been seen yet but users dealing with untrusted content are at heightened risk.

    1000035
    315 followersView on X
  • transilienceai@transilienceai
    Patch

    @decernly 🚨 Adobe After Effects versions 25.6 and earlier contain multiple critical vulnerabilities, including CVE-2026-21319 (out-of-bounds read, CWE-125). This was addressed in Adobe Security Bulletin APSB26-15 released on February 10, 2026. #Adobe #AfterEffects

    Post summary

    Adobe After Effects 25.6 and earlier are affected by CVE-2026-21319, an out‑of‑bounds read vulnerability that was patched in the February 10, 2026 security bulletin, with no evidence of exploitation or PoC.

    1000055
    315 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21319 After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulner… https://www.cve.org/CVERecord?id=CVE-2026-21319

    Post summary

    The text announces a newly disclosed Out-of-bounds Read vulnerability in After Effects versions 25.6 and earlier, detailing the impact but providing no exploit, PoC, patch, or active exploitation evidence.

    00000108
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeafter_effects---
OSapplemacos---
OSmicrosoftwindows---

Explore more