CVE-2026-21316Medium· 5.5▾ SunlitAudition versions 25.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
0.1% → 0.1%
Audition versions 25.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
audition < 25.6Upgrade past the affected range:
audition 25.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-21317Medium· 5.5Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure
CVE-2026-21315Medium· 5.5Audition versions 25.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure
CVE-2026-21314Medium· 5.5Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure
CVE-2026-21313Medium· 5.5Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure
CVE-2026-21312High· 7.8Audition versions 25.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-84397Medium· 5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields