ZeroHour

CVE-2026-75991

mass

Arbitrary Code Execution via Improper Input Validation in Adobe Illustrator

CVSS 3.1
8.6 high
EPSS
<1%p12
Published
()
Modified
AI analysis

Adobe Illustrator contains an improper input validation flaw (CWE-20) that allows arbitrary code execution in the context of the current user when the application processes specially crafted input. The issue is triggered when a victim opens a malicious file, such as a crafted Illustrator document, so user interaction is required; the changed-scope designation means successful exploitation can affect resources beyond the vulnerable component's own security boundary. An attacker who succeeds gains code execution with the privileges of the logged-in user, with high impact to confidentiality, integrity, and availability. Anyone running an affected version of the Adobe Illustrator desktop application is exposed; the source data does not list specific affected version ranges. There is no known exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS estimates only about a 0.2% chance of exploitation in the next 30 days.

What to do: Check which version of Illustrator is installed on endpoints and update via Creative Cloud to the latest release identified as fixed in Adobe's security advisory for this CVE, since the source data does not include the exact fixed version. Until patched, avoid opening .ai and other Illustrator documents from untrusted or unexpected sources, especially attachments delivered by email or dropped into shared locations. Monitor Adobe's bulletin for the confirmed affected/fixed version ranges and prioritize systems where users regularly open third-party files.

Affected
Adobe Illustrator
Estimated exposure
massmillions of users (Creative Cloud subscriber base; per-app install counts not published) — Adobe does not publish per-application install counts, but Creative Cloud has on the order of tens of millions of subscribers and Illustrator is one of its flagship desktop applications, so affected installs are plausibly in the millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.