After Effects
Vendor:
First CVE: Aug 14, 2019 · Active for 6 years
127
Total CVEs
More Total CVEs than 99% of tracked products
15.9
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact After Effects over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2019
6 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
After Effects127 CVEs
9%
22%
68%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local125 (98.4%)
Network2 (1.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low127 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (0.8%)
Unknown0 (0.0%)
Required126 (99.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None127 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (127 CVEs).
127 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-3765CRITICAL Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | Feb 20, 2020 | 9.8 | 33 | NO | NO |
CVE-2026-48367HIGH After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi | Jul 14, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-48274HIGH After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi | Jul 14, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-34690HIGH After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu | May 12, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-34644HIGH After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the | May 12, 2026 | 7.8 | 28 | NO | NO |
CVE-2026-34643HIGH After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current use | May 12, 2026 | 7.8 | 28 | NO | NO |
CVE-2026-34642HIGH After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the curre | May 12, 2026 | 7.8 | 28 | NO | NO |
CVE-2021-28571HIGH Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. | Sep 8, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-9638HIGH Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution . | Jun 25, 2020 | 7.8 | 28 | NO | NO |
CVE-2020-9637HIGH Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution . | Jun 25, 2020 | 7.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (127 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (127 CVEs).
Media Mentions
Signals from CVEs in this product scope (127 CVEs).
Top CNAs Publishing CVEs For After Effects
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 26.0 | 3 | 7.8 | 0.2% | 0 | 0 |