Animate Adobe Animate

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Adobe Animate.

Recent Adobe Animate Security Advisories

Advisory Title Published
APSB26-83 Security updates available for Adobe Animate | APSB26-83 July 14, 2026
APSB25-97 Security updates available for Adobe Animate | APSB25-97 October 14, 2025
APSB25-73 Security updates available for Adobe Animate | APSB25-73 August 12, 2025
APSB25-42 Security updates available for Adobe Animate | APSB25-42 May 13, 2025
APSB25-31 Security updates available for Adobe Animate | APSB25-31 April 8, 2025
APSB25-05 Security updates available for Adobe Animate | APSB25-05 January 14, 2025
APSB24-96 Security updates available for Adobe Animate | APSB24-96 December 10, 2024
APSB24-76 Security updates available for Adobe Animate | APSB24-76 October 8, 2024
APSB24-36 Security updates available for Adobe Animate | APSB24-36 May 14, 2024
APSB24-26 Security updates available for Adobe Animate | APSB23-61 APSB24-26 April 9, 2024

By the Year

In 2026 there have been 6 vulnerabilities in Adobe Animate with an average score of 8.0 out of ten. Last year, in 2025 Animate had 16 security vulnerabilities published. Right now, Animate is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.10.




Year Vulnerabilities Average Score
2026 6 8.03
2025 16 6.94
2024 42 7.35
2023 5 7.34
2022 2 7.80
2021 7 7.37
2020 4 7.80
2019 1 0.00

It may take a day or so for new Animate vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Adobe Animate Security Vulnerabilities

Adobe Animate Untrusted Search Path CVE-2026-48346 Code Exec
CVE-2026-48346 7.9 - High - July 14, 2026

Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Untrusted Path

OS Command Injection in Adobe Animate via malicious file
CVE-2026-48345 8.2 - High - July 14, 2026

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Shell injection

Adobe Animate OS Command Injection via Malicious File (CVE-2026-48347)
CVE-2026-48347 7.7 - High - July 14, 2026

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Shell injection

Adobe Animate Incorrect Auth Enables Arbitrary Code Execution (CVE-2026-48349)
CVE-2026-48349 8.1 - High - July 14, 2026

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

AuthZ

Adobe Animate Auth RCE via Malicious File
CVE-2026-48348 7.7 - High - July 14, 2026

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

AuthZ

Adobe Animate Path Traversal Causing Arbitrary Code Execution
CVE-2026-48350 8.6 - High - July 14, 2026

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Directory traversal

Adobe Animate <=24.0.10: Heap BF Vulnerability
CVE-2025-61804 7.8 - High - October 15, 2025

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Animate <24.0.10 UK Use After Free RCE
CVE-2025-54279 7.8 - High - October 15, 2025

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Animate <=24.0.10 out-of-bounds read may expose memory
CVE-2025-54269 5.5 - Medium - October 15, 2025

Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Animate <23.0.13 NULL Deref Memory Exposure
CVE-2025-54270 5.5 - Medium - October 15, 2025

Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NULL Pointer Dereference

Adobe Animate UAF before 24.0.9 leads to memory disclosure
CVE-2025-49562 5.5 - Medium - August 12, 2025

Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate UAF v23.0.12/24.0.9
CVE-2025-49561 7.8 - High - August 12, 2025

Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate OOB Write CVE-2025-30328 Enables Arbitrary Code Execution
CVE-2025-30328 7.8 - High - May 13, 2025

Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Animate <24.0.8 Integer Underflow Vulnerability (CVE-2025-43555)
CVE-2025-43555 7.8 - High - May 13, 2025

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate <=24.0.8 Integer Overflow Allows Arbitrary Code Execution
CVE-2025-43556 7.8 - High - May 13, 2025

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Adobe Animate NULL Pointer Deref, DoS v24.0.8 & 23.0.11
CVE-2025-30329 5.5 - Medium - May 13, 2025

Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NULL Pointer Dereference

Adobe Animate <=23.0.11/24.0.8: Uninitialized Pointer RCE via Malicious File
CVE-2025-43557 7.8 - High - May 13, 2025

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Adobe Animate OOB Read CVE-2025-27202 (v24.0.7, v23.0.10)
CVE-2025-27202 5.5 - Medium - April 08, 2025

Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Animate OOB Read in Pre-24.0.7 – Sensitive Memory Disclosure
CVE-2025-27201 5.5 - Medium - April 08, 2025

Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Animate <24.0.8 Use-After-Free (UAF) RCE via Malicious File
CVE-2025-27200 7.8 - High - April 08, 2025

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate <=24.0.7 Heap Buffer Overflow
CVE-2025-27199 7.8 - High - April 08, 2025

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Animate 22-24.0.6 Integer Underflow (Wrap) allows Arbitrary Code Execution
CVE-2025-21135 7.8 - High - January 14, 2025

Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate Improper Input Validation Arbitrary Code Execution Vulnerability
CVE-2024-52982 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Improper Input Validation

Adobe Animate Integer Overflow Vulnerability
CVE-2024-52983 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Adobe Animate Integer Underflow Vulnerability
CVE-2024-52984 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate Integer Underflow Vulnerability
CVE-2024-52985 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate Integer Underflow Vulnerability
CVE-2024-52987 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate Out-of-Bounds Write Vulnerability
CVE-2024-52988 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Animate Integer Underflow Vulnerability
CVE-2024-52989 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate Buffer Underwrite Vulnerability
CVE-2024-52990 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to manipulate memory in such a way that they could execute code under the privileges of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

buffer underrun

Adobe Animate <=24.0.5 Uninitialized Pointer -> Arbitrary Code Exec
CVE-2024-45155 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Adobe Animate <=24.0.5 NULL Deref Arbitrary Code Exec (CVE-2024-45156)
CVE-2024-45156 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NULL Pointer Dereference

Adobe Animate Use After Free Vulnerability in Animation Engine
CVE-2024-53953 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate Integer Underflow Vulnerability
CVE-2024-53954 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate Integer Underflow Vulnerability
CVE-2024-52986 7.8 - High - December 10, 2024

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Adobe Animate <=23.0.7/24.0.4 OOB Write Arbitrary Exec
CVE-2024-49528 7.8 - High - November 12, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Animate 23.x/24.x OOB Read Vulnerability
CVE-2024-49527 5.5 - Medium - November 12, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Animate UA-Free v23.0.7/24.0.4 Code Exec via Malicious File
CVE-2024-49526 7.8 - High - November 12, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate Stack Buffer Overflow (<=24.0.4) Enables Code Exec
CVE-2024-47410 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Animate <24.0.4 UAFO CVE-2024-47418 Arbitrary Code Exec
CVE-2024-47418 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate OOB Read in v23.0.7/24.0.4 memory disclosure via malicious file.
CVE-2024-47419 5.5 - Medium - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

OOB Read Disclosure in Adobe Animate 23.0.7-24.0.4 (CVE-2024-47420)
CVE-2024-47420 5.5 - Medium - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Heap-buffer-overflow in Adobe Animate 23.0.7/24.0.4 & earlier
CVE-2024-47417 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Animate 23.0.7/24.0.4 Int Overflow: Arbitrary Exec via Malicious File
CVE-2024-47416 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Adobe Animate V23.0.7/24.0.4 UAF Arbitrary Code Execution
CVE-2024-47415 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate <=23.0.7 UAF via malicious file
CVE-2024-47414 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Use-After-Free in Adobe Animate 23.0.7/24.0.4
CVE-2024-47413 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate Use After Free Vulnerability 24.0.4
CVE-2024-47412 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Animate 23.0.7/24.0.4 Uninitialized Pointer Arbitrary Code Exec
CVE-2024-47411 7.8 - High - October 09, 2024

Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Adobe Animate OOB Write v24.0.2/v23.0.5 Allows Arbitrary Code Execution
CVE-2024-30282 7.8 - High - May 16, 2024

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Adobe Animate or by Adobe? Click the Watch button to subscribe.

Adobe
Vendor

Adobe Animate
Product

subscribe