CVE-2026-75992
massOut-of-bounds write in Adobe Illustrator allows code execution when opening files
Adobe Illustrator contains an out-of-bounds write flaw (CWE-787) when processing crafted files, which can corrupt memory beyond the intended buffer. Triggering it requires user interaction: a victim must open a malicious file, and the attack vector is local (CVSS AV:L with UI:R). If successfully exploited, an attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability. Anyone running an affected build of Illustrator is exposed, although the available data does not specify which version ranges are affected. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Update Illustrator to the fixed release listed in Adobe's security bulletin, using the Creative Cloud desktop app's update mechanism since affected versions were not specified in this data. Until updated, do not open Illustrator or other design files from untrusted or unverified sources, as exploitation requires opening a malicious file. Prioritize workstations that routinely receive files from external parties.
| Adobe Illustrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.