Description
Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Illustrator is vulnerable to an out‑of‑bounds read that can expose data residing in memory. The flaw allows an attacker to read beyond a buffer boundary, potentially revealing confidential information. The issue is categorized as CWE‑125 and is triggered when a malicious file is opened by the application.

Affected Systems

Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are affected. No additional sub‑versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the absence of an EPSS score means exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: an unsuspecting victim must open a crafted AI file, making it a user‑dependent threat.

Generated by OpenCVE AI on August 25, 2026 at 20:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Adobe Illustrator patch released under the APSS‑26‑124 advisory.
  • Limit the opening of AI files to trusted sources only, disabling automatic processing of unverified files.
  • Use sandboxing or isolated workstations to handle unfamiliar AI files before allowing them to run in the main environment.

Generated by OpenCVE AI on August 25, 2026 at 20:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026
Vendors & Products Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Illustrator | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Illustrator Desktop 2025 Illustrator Desktop 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:49:59.846Z

Reserved: 2026-08-06T16:40:07.109Z

Link: CVE-2026-71441

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:01.173

Modified: 2026-08-25T18:18:01.173

Link: CVE-2026-71441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses