Description
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-09-08
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Adobe Illustrator Desktop is vulnerable to an improper input validation flaw that can lead to arbitrary code execution when the user opens a crafted file. The flaw allows an attacker to inject malicious code into the application’s processing path, enabling execution within the context of the current user. Successful exploitation can compromise user data and facilitate further attacks, and the vulnerability’s scope is changed.

Affected Systems

Both Adobe Illustrator Desktop 2025 and 2026 contain the input validation bug that can be triggered by malicious files. No other Illustrator releases are listed as affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and the flaw requires the victim to open a malicious file, which lowers the probability of successful attack attempts. The EPSS score is currently unavailable and the vulnerability is not in the CISA KEV catalog, indicating that large‑scale exploitation has not been observed yet. Nevertheless, the change in scope and ability to run code arbitrarily mean the vulnerability poses a serious risk to systems that use Illustrator when exposed to untrusted documents.

Generated by OpenCVE AI on September 9, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Adobe Illustrator security update (APSB26-131) as soon as it is released.
  • Disable Illustrator’s auto‑run feature for opening files until the patch is applied.
  • Instruct users to avoid opening or dragging files from untrusted sources into Illustrator.

Generated by OpenCVE AI on September 9, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe illustrator
CPEs cpe:2.3:a:adobe:illustrator:*:*:*:*:*:*:*:*
Vendors & Products Adobe illustrator

Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026
Vendors & Products Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Illustrator | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Illustrator Illustrator Desktop 2025 Illustrator Desktop 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:44.118Z

Reserved: 2026-08-18T18:43:30.983Z

Link: CVE-2026-75991

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:55.164Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:23.247

Modified: 2026-09-18T14:21:22.707

Link: CVE-2026-75991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T15:45:16Z

Weaknesses
  • CWE-20

    Improper Input Validation