.

Adobe Security Bulletin

Last updated on Jul 14, 2026

Security updates available for Adobe Animate | APSB26-83

Bulletin ID
Date published
Priority
APSB26-83
July 14, 2026
3

Summary

Adobe has released an update for Adobe Animate. This update resolves critical vulnerabilities. Successful exploitation could lead to arbitrary code execution.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.

Affected Versions

Product
Version
Platform
Adobe Animate 2023
23.0.15 and earlier versions
Windows and macOS
Adobe Animate 2024
24.0.13 and earlier versions
Windows and macOS

Solution

Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version via the Creative Cloud desktop app's update mechanism. For more information, please reference this help page.

For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information.

Product
Version
Platform
Priority
Availability
Adobe Animate 2023
23.0.16
Windows and macOS
3
Adobe Animate 2024
24.0.14
Windows and macOS
3

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary code execution
Critical
8.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48350
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Arbitrary code execution
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48345
Untrusted Search Path (CWE-426)
Arbitrary code execution
Critical
7.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVE-2026-48346
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Arbitrary code execution
Critical
7.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48347
Incorrect Authorization (CWE-863)
Arbitrary code execution
Critical
7.7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48348
Incorrect Authorization (CWE-863)
Arbitrary code execution
Critical
7.7
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48349

Acknowledgments

Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:

  • Kieran (kaiksi) - CVE-2026-48345, CVE-2026-48346, CVE-2026-48347, CVE-2026-48348, CVE-2026-48349, CVE-2026-48350