After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
History

Tue, 10 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Description After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title After Effects | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-02-10T17:52:57.874Z

Reserved: 2025-12-12T22:01:18.194Z

Link: CVE-2026-21330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-10T18:16:30.990

Modified: 2026-02-10T18:16:30.990

Link: CVE-2026-21330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.