ZeroHour

CVE-2026-75992

mass

Out-of-bounds write in Adobe Illustrator allows code execution when opening files

CVSS 3.1
7.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Adobe Illustrator contains an out-of-bounds write flaw (CWE-787) when processing crafted files, which can corrupt memory beyond the intended buffer. Triggering it requires user interaction: a victim must open a malicious file, and the attack vector is local (CVSS AV:L with UI:R). If successfully exploited, an attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability. Anyone running an affected build of Illustrator is exposed, although the available data does not specify which version ranges are affected. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Update Illustrator to the fixed release listed in Adobe's security bulletin, using the Creative Cloud desktop app's update mechanism since affected versions were not specified in this data. Until updated, do not open Illustrator or other design files from untrusted or unverified sources, as exploitation requires opening a malicious file. Prioritize workstations that routinely receive files from external parties.

Affected
Adobe Illustrator
Estimated exposure
massmillions of users (Illustrator is a flagship Adobe Creative Cloud desktop application) — Adobe Creative Cloud has a subscriber base in the tens of millions and Illustrator is one of its flagship desktop applications, so the installed base plausibly exceeds one million users, though exact figures are not in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.