Description
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write in Adobe Illustrator allows an attacker to overwrite data structures, enabling arbitrary code execution when a victim opens a crafted file. The flaw is a classic buffer overrun (CWE‑787) that, if successfully exploited, grants the attacker the rights of the current user, potentially allowing system‑wide compromise, data theft, or installation of persistent malware. The description states that the victim must interact by opening a malicious file, so the impact is contingent on user action.

Affected Systems

The vulnerability is present in Adobe Illustrator Desktop 2025 and 2026 releases. Users with either of these versions are affected; versions prior to 2025 and any other Adobe product are not mentioned as impacted.

Risk and Exploitability

The CVSS score of 7.8 reflects high severity, but the EPSS score is not provided, suggesting limited publicly known exploitation. The flaw requires user interaction, making it a “bad‑actor” style threat rather than an automated network exploit. Since the vulnerability is not listed in the CISA KEV catalog, it is not confirmed as currently exploited in the wild, though the high score indicates that if it were, the impact could be severe.

Generated by OpenCVE AI on September 9, 2026 at 13:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Illustrator security update that addresses the out‑of‑bounds write (refer to Adobe’s security bulletin for version details).
  • Configure Illustrator to block or warn before opening unknown or suspicious file types, and disable auto‑execution of scripts that could be embedded in malicious files.
  • Implement file‑type filtering or sandboxing in your email/file‑sharing workflow to ensure that potentially malicious files are quarantined before a user can open them.

Generated by OpenCVE AI on September 9, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe illustrator
CPEs cpe:2.3:a:adobe:illustrator:*:*:*:*:*:*:*:*
Vendors & Products Adobe illustrator

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026
Vendors & Products Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Illustrator | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Illustrator Illustrator Desktop 2025 Illustrator Desktop 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:44.262Z

Reserved: 2026-08-18T18:43:30.984Z

Link: CVE-2026-75992

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:57.415Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:23.373

Modified: 2026-09-18T14:18:36.687

Link: CVE-2026-75992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T21:45:03Z

Weaknesses