Junglewise Threat Intelligence

CVE-2026-21333: Adobe Illustrator untrusted search path arbitrary code execution

CVE-2026-21333 · Severity: high · CVSS 8.6 · Published 2026-03-10

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator is a professional graphics design application widely used by designers and creative professionals. Versions 29.8.4, 30.1 and earlier contain a vulnerability that allows attackers to execute arbitrary code on a user's computer by tricking them into opening a specially crafted file. This could lead to complete system compromise, data theft, or malware installation on affected machines.

Technical details

An untrusted search path vulnerability in Adobe Illustrator versions 29.8.4 and 30.1 and earlier allows arbitrary code execution in the context of the current user. The vulnerability is triggered when a victim opens a malicious file, indicating the attack vector requires social engineering or user interaction. An attacker can exploit this to execute arbitrary code with the privileges of the user running Illustrator. No active exploitation in the wild has been reported at the time of disclosure. Adobe has issued patches to address this issue.

Affected products

  • Adobe Illustrator 29.8.4, 30.1 and earlier

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: APSB26-18

References

Related threats