ZeroHour

CVE-2026-76191

mass

Code Injection in Adobe Animate allows arbitrary code execution via malicious files

CVSS 3.1
8.2 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Adobe Animate contains an improper control of code generation (CWE-94, code injection) vulnerability that allows arbitrary code execution in the context of the current user. Exploitation is local and requires user interaction: a low-privileged attacker must get a victim to open a malicious file, presumably a crafted Animate project or animation file. Because the CVSS scope is changed, successful exploitation runs attacker-controlled code beyond the vulnerable component, giving the attacker code execution with the victim's privileges, which can enable data theft or malware deployment. Users running Adobe Animate are affected; the source data does not specify which releases are vulnerable or fixed, so consult Adobe's advisory for exact version ranges. As of publication there is no known exploitation, no public proof of concept, the issue is not in CISA KEV, and EPSS estimates a 0.3% probability of exploitation within 30 days.

What to do: Check Adobe's security bulletin for this CVE and update Animate to the fixed release it lists, prioritizing workstations where users open animation or project files from external sources. Until patched, avoid opening Animate files from untrusted senders and treat unexpected dialogs or child processes spawned by Animate as suspicious. Because this is a local, user-triggered flaw, standard desktop patch cadence applies unless high-value or creative-team endpoints are exposed.

Affected
Adobe Animate
Estimated exposure
mass≈1M+ installed users (Animate is a long-standing app within Adobe's roughly 30M-subscriber Creative Cloud ecosystem) — Adobe does not publish per-application seat counts, so this order-of-magnitude estimate is derived from Creative Cloud's large subscriber base and Animate's decades-long inclusion in it; actively used seats are likely a subset.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Vendors
adobe
Products
animate
Weakness
CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.