Back Heise.De Patch day at Adobe: After Effects & Co. vulnerable to malware attacks
Adobe has fixed its applications Bridge, After Effects, Audition, DNG Software Development Kit (SDK), InDesign, Lightroom Classic, Substance 3D Designer, Substance 3D Modeler, and Substance 3D Stager. Those who do not install the security updates risk attackers executing malicious code on computers. Adobe states that they currently have no indications of attacks.
The software manufacturer classifies the majority of the security vulnerabilities as “critical.” In most cases, the versions for macOS and Windows are vulnerable, and attackers can execute malicious code. This usually leads to the complete compromise of systems.
Examples include vulnerabilities in Substance 3D Stager ( CVE-2026-21341 “ high ”) and After Effects ( CVE-2026-21318 “ high ”). For malicious code to reach systems, attackers must trigger memory errors (e.g., Use After Free) through an unspecified method.
Adobe's developers assure that the security issues have been resolved in the following versions:
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
