Adobe Animate
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Adobe Animate.
Recent Adobe Animate Security Advisories
| Advisory | Title | Published |
|---|---|---|
| APSB26-83 | Security updates available for Adobe Animate | APSB26-83 | July 14, 2026 |
| APSB25-97 | Security updates available for Adobe Animate | APSB25-97 | October 14, 2025 |
| APSB25-73 | Security updates available for Adobe Animate | APSB25-73 | August 12, 2025 |
| APSB25-42 | Security updates available for Adobe Animate | APSB25-42 | May 13, 2025 |
| APSB25-31 | Security updates available for Adobe Animate | APSB25-31 | April 8, 2025 |
| APSB25-05 | Security updates available for Adobe Animate | APSB25-05 | January 14, 2025 |
| APSB24-96 | Security updates available for Adobe Animate | APSB24-96 | December 10, 2024 |
| APSB24-76 | Security updates available for Adobe Animate | APSB24-76 | October 8, 2024 |
| APSB24-36 | Security updates available for Adobe Animate | APSB24-36 | May 14, 2024 |
| APSB24-26 | Security updates available for Adobe Animate | APSB23-61 APSB24-26 | April 9, 2024 |
By the Year
In 2026 there have been 6 vulnerabilities in Adobe Animate with an average score of 8.0 out of ten. Last year, in 2025 Animate had 16 security vulnerabilities published. Right now, Animate is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.10.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 8.03 |
| 2025 | 16 | 6.94 |
| 2024 | 42 | 7.35 |
| 2023 | 5 | 7.34 |
| 2022 | 2 | 7.80 |
| 2021 | 7 | 7.37 |
| 2020 | 4 | 7.80 |
| 2019 | 1 | 0.00 |
It may take a day or so for new Animate vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Adobe Animate Security Vulnerabilities
Adobe Animate Untrusted Search Path CVE-2026-48346 Code Exec
CVE-2026-48346
7.9 - High
- July 14, 2026
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Untrusted Path
OS Command Injection in Adobe Animate via malicious file
CVE-2026-48345
8.2 - High
- July 14, 2026
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Shell injection
Adobe Animate OS Command Injection via Malicious File (CVE-2026-48347)
CVE-2026-48347
7.7 - High
- July 14, 2026
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Shell injection
Adobe Animate Incorrect Auth Enables Arbitrary Code Execution (CVE-2026-48349)
CVE-2026-48349
8.1 - High
- July 14, 2026
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
Adobe Animate Auth RCE via Malicious File
CVE-2026-48348
7.7 - High
- July 14, 2026
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
AuthZ
Adobe Animate Path Traversal Causing Arbitrary Code Execution
CVE-2026-48350
8.6 - High
- July 14, 2026
Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Directory traversal
Adobe Animate <=24.0.10: Heap BF Vulnerability
CVE-2025-61804
7.8 - High
- October 15, 2025
Animate versions 23.0.13, 24.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Animate <24.0.10 UK Use After Free RCE
CVE-2025-54279
7.8 - High
- October 15, 2025
Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Animate <=24.0.10 out-of-bounds read may expose memory
CVE-2025-54269
5.5 - Medium
- October 15, 2025
Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Animate <23.0.13 NULL Deref Memory Exposure
CVE-2025-54270
5.5 - Medium
- October 15, 2025
Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NULL Pointer Dereference
Adobe Animate UAF before 24.0.9 leads to memory disclosure
CVE-2025-49562
5.5 - Medium
- August 12, 2025
Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate UAF v23.0.12/24.0.9
CVE-2025-49561
7.8 - High
- August 12, 2025
Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate OOB Write CVE-2025-30328 Enables Arbitrary Code Execution
CVE-2025-30328
7.8 - High
- May 13, 2025
Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Animate <24.0.8 Integer Underflow Vulnerability (CVE-2025-43555)
CVE-2025-43555
7.8 - High
- May 13, 2025
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate <=24.0.8 Integer Overflow Allows Arbitrary Code Execution
CVE-2025-43556
7.8 - High
- May 13, 2025
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Adobe Animate NULL Pointer Deref, DoS v24.0.8 & 23.0.11
CVE-2025-30329
5.5 - Medium
- May 13, 2025
Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NULL Pointer Dereference
Adobe Animate <=23.0.11/24.0.8: Uninitialized Pointer RCE via Malicious File
CVE-2025-43557
7.8 - High
- May 13, 2025
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Access of Uninitialized Pointer
Adobe Animate OOB Read CVE-2025-27202 (v24.0.7, v23.0.10)
CVE-2025-27202
5.5 - Medium
- April 08, 2025
Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Animate OOB Read in Pre-24.0.7 – Sensitive Memory Disclosure
CVE-2025-27201
5.5 - Medium
- April 08, 2025
Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Animate <24.0.8 Use-After-Free (UAF) RCE via Malicious File
CVE-2025-27200
7.8 - High
- April 08, 2025
Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate <=24.0.7 Heap Buffer Overflow
CVE-2025-27199
7.8 - High
- April 08, 2025
Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Animate 22-24.0.6 Integer Underflow (Wrap) allows Arbitrary Code Execution
CVE-2025-21135
7.8 - High
- January 14, 2025
Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate Improper Input Validation Arbitrary Code Execution Vulnerability
CVE-2024-52982
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Improper Input Validation
Adobe Animate Integer Overflow Vulnerability
CVE-2024-52983
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Adobe Animate Integer Underflow Vulnerability
CVE-2024-52984
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate Integer Underflow Vulnerability
CVE-2024-52985
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate Integer Underflow Vulnerability
CVE-2024-52987
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate Out-of-Bounds Write Vulnerability
CVE-2024-52988
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Animate Integer Underflow Vulnerability
CVE-2024-52989
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate Buffer Underwrite Vulnerability
CVE-2024-52990
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to manipulate memory in such a way that they could execute code under the privileges of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
buffer underrun
Adobe Animate <=24.0.5 Uninitialized Pointer -> Arbitrary Code Exec
CVE-2024-45155
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Access of Uninitialized Pointer
Adobe Animate <=24.0.5 NULL Deref Arbitrary Code Exec (CVE-2024-45156)
CVE-2024-45156
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NULL Pointer Dereference
Adobe Animate Use After Free Vulnerability in Animation Engine
CVE-2024-53953
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate Integer Underflow Vulnerability
CVE-2024-53954
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate Integer Underflow Vulnerability
CVE-2024-52986
7.8 - High
- December 10, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Adobe Animate <=23.0.7/24.0.4 OOB Write Arbitrary Exec
CVE-2024-49528
7.8 - High
- November 12, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Animate 23.x/24.x OOB Read Vulnerability
CVE-2024-49527
5.5 - Medium
- November 12, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Animate UA-Free v23.0.7/24.0.4 Code Exec via Malicious File
CVE-2024-49526
7.8 - High
- November 12, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate Stack Buffer Overflow (<=24.0.4) Enables Code Exec
CVE-2024-47410
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Animate <24.0.4 UAFO CVE-2024-47418 Arbitrary Code Exec
CVE-2024-47418
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate OOB Read in v23.0.7/24.0.4 memory disclosure via malicious file.
CVE-2024-47419
5.5 - Medium
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
OOB Read Disclosure in Adobe Animate 23.0.7-24.0.4 (CVE-2024-47420)
CVE-2024-47420
5.5 - Medium
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Heap-buffer-overflow in Adobe Animate 23.0.7/24.0.4 & earlier
CVE-2024-47417
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Animate 23.0.7/24.0.4 Int Overflow: Arbitrary Exec via Malicious File
CVE-2024-47416
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Adobe Animate V23.0.7/24.0.4 UAF Arbitrary Code Execution
CVE-2024-47415
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate <=23.0.7 UAF via malicious file
CVE-2024-47414
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Use-After-Free in Adobe Animate 23.0.7/24.0.4
CVE-2024-47413
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate Use After Free Vulnerability 24.0.4
CVE-2024-47412
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Animate 23.0.7/24.0.4 Uninitialized Pointer Arbitrary Code Exec
CVE-2024-47411
7.8 - High
- October 09, 2024
Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Access of Uninitialized Pointer
Adobe Animate OOB Write v24.0.2/v23.0.5 Allows Arbitrary Code Execution
CVE-2024-30282
7.8 - High
- May 16, 2024
Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Adobe Animate or by Adobe? Click the Watch button to subscribe.