ZeroHour

CVE-2026-75990

mass

Incorrect Authorization in Adobe Illustrator allows code execution via malicious files

CVSS 3.1
8.6 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Illustrator contains an incorrect authorization flaw (CWE-863) that fails to properly enforce access checks, which could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction: a victim must open a malicious file (e.g., an untrusted Illustrator document) for the attacker's code to run, and the local attack vector means the attacker cannot trigger it remotely on their own. The 'scope changed' designation in the CVSS vector indicates the flaw can cross a security boundary, letting an attacker execute code beyond the initially affected component with the victim user's privileges. All Illustrator users who open files from untrusted or unsolicited sources are potentially affected; the available data does not specify affected version ranges. There is currently no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days (10th percentile).

What to do: Update Illustrator to the patched build listed in Adobe's security bulletin (fixed version not specified in the available data) via the Creative Cloud desktop app and verify the installed version against the advisory. Until patched, avoid opening Illustrator files from untrusted or unsolicited sources, since exploitation requires user interaction to open a malicious file.

Affected
Adobe Illustrator
Estimated exposure
massmillions of users (order of 10M+; exact Illustrator install counts are not published) — Adobe does not disclose per-application install counts, but Illustrator is a flagship Creative Cloud application serving a subscriber base Adobe has publicly described in the tens of millions, so the plausibly exposed user base is well…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.