CVE-2026-75991
massArbitrary Code Execution via Improper Input Validation in Adobe Illustrator
Adobe Illustrator contains an improper input validation flaw (CWE-20) that allows arbitrary code execution in the context of the current user when the application processes specially crafted input. The issue is triggered when a victim opens a malicious file, such as a crafted Illustrator document, so user interaction is required; the changed-scope designation means successful exploitation can affect resources beyond the vulnerable component's own security boundary. An attacker who succeeds gains code execution with the privileges of the logged-in user, with high impact to confidentiality, integrity, and availability. Anyone running an affected version of the Adobe Illustrator desktop application is exposed; the source data does not list specific affected version ranges. There is no known exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS estimates only about a 0.2% chance of exploitation in the next 30 days.
What to do: Check which version of Illustrator is installed on endpoints and update via Creative Cloud to the latest release identified as fixed in Adobe's security advisory for this CVE, since the source data does not include the exact fixed version. Until patched, avoid opening .ai and other Illustrator documents from untrusted or unexpected sources, especially attachments delivered by email or dropped into shared locations. Monitor Adobe's bulletin for the confirmed affected/fixed version ranges and prioritize systems where users regularly open third-party files.
| Adobe Illustrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.