Junglewise Threat Intelligence

CVE-2026-21362: Adobe Illustrator out-of-bounds write

CVE-2026-21362 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator is a professional graphics design application used to create vector artwork, logos, and illustrations. A memory corruption vulnerability in the application allows an attacker to execute arbitrary code with the privileges of the logged-in user by tricking them into opening a specially crafted file. This could lead to unauthorized access to sensitive design files, customer data, or serve as a foothold for further system compromise.

Technical details

The vulnerability is an out-of-bounds write flaw in Adobe Illustrator versions 29.8.4 and 30.1 and earlier. The vulnerability can be exploited to execute arbitrary code in the context of the current user. The attack requires user interaction—a victim must open a malicious file (e.g., a specially crafted Illustrator document). No authentication or network access is required beyond the user's interaction with the malicious file. Successful exploitation results in arbitrary code execution with the privileges of the user running Illustrator.

Affected products

  • Adobe Illustrator 29.8.4, 30.1 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats