---
id: CVE-2026-21330
title: >-
  After Effects versions 25.6 and earlier are affected by an Access of Resource
  Using Incompatible Type ('Type Confusion') vulnerability that could result in
  arbitrary code execution in the context of the current user
summary: >-
  After Effects versions 25.6 and earlier are affected by an Access of Resource
  Using Incompatible Type ('Type Confusion') vulnerability that could result in
  arbitrary code execution in the context of the current user. Exploitation of
  this…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-843
vendor: adobe
product: after_effects
affected:
  - after_effects < 25.6.4
patched:
  - after_effects 25.6.4
published: '2026-02-10'
updated: '2026-08-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21330'
references:
  - url: 'https://helpx.adobe.com/security/products/after_effects/apsb26-15.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00219
epssPercentile: 0.1093
ingestedAt: '2026-08-27T21:08:16.163Z'
---

## Overview

After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `after_effects < 25.6.4`

## Remediation

Upgrade past the affected range:

- `after_effects 25.6.4`
