CVE-2026-76191
massCode Injection in Adobe Animate allows arbitrary code execution via malicious files
Adobe Animate contains an improper control of code generation (CWE-94, code injection) vulnerability that allows arbitrary code execution in the context of the current user. Exploitation is local and requires user interaction: a low-privileged attacker must get a victim to open a malicious file, presumably a crafted Animate project or animation file. Because the CVSS scope is changed, successful exploitation runs attacker-controlled code beyond the vulnerable component, giving the attacker code execution with the victim's privileges, which can enable data theft or malware deployment. Users running Adobe Animate are affected; the source data does not specify which releases are vulnerable or fixed, so consult Adobe's advisory for exact version ranges. As of publication there is no known exploitation, no public proof of concept, the issue is not in CISA KEV, and EPSS estimates a 0.3% probability of exploitation within 30 days.
What to do: Check Adobe's security bulletin for this CVE and update Animate to the fixed release it lists, prioritizing workstations where users open animation or project files from external sources. Until patched, avoid opening Animate files from untrusted senders and treat unexpected dialogs or child processes spawned by Animate as suspicious. Because this is a local, user-triggered flaw, standard desktop patch cadence applies unless high-value or creative-team endpoints are exposed.
| Adobe Animate | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- Vendors
- adobe
- Products
- animate
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.