Junglewise Threat Intelligence

CVE-2026-21288: Adobe Illustrator null pointer dereference leading to denial of service

CVE-2026-21288 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator, a widely used graphic design and illustration application, contains a null pointer dereference flaw that can be triggered when a user opens a specially crafted file. An attacker can exploit this vulnerability to crash the application, disrupting the victim's work and productivity.

Technical details

The vulnerability is a null pointer dereference in Adobe Illustrator versions 29.8.3, 30.0 and earlier. An attacker can craft a malicious file that, when opened by a victim in Illustrator, causes the application to crash due to improper pointer handling. The attack requires user interaction (opening a malicious file) but no special privileges. The impact is denial of service—the application becomes unavailable, though no data corruption or code execution occurs. Patches are expected from Adobe.

Affected products

  • Adobe Illustrator 29.8.3, 30.0 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats