Junglewise Threat Intelligence

CVE-2026-27267: Adobe Illustrator stack-based buffer overflow

CVE-2026-27267 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator is a widely used professional graphics design application. A stack-based buffer overflow vulnerability in versions 29.8.4 and 30.1 could allow attackers to execute arbitrary code on a user's computer by tricking them into opening a malicious file. Successful exploitation would grant an attacker complete control over the victim's system with the privileges of the logged-in user.

Technical details

A stack-based buffer overflow vulnerability exists in Adobe Illustrator versions 29.8.4 and earlier in the 30.x branch (30.1 and earlier). The vulnerability is triggered when processing a specially crafted file, causing a stack buffer to overflow and enabling arbitrary code execution in the context of the current user. Exploitation requires user interaction—a victim must be socially engineered to open a malicious file. No patch availability information is provided in the advisory, though the CVE number suggests this is a known and documented issue. The CVSS score of 7.8 reflects high severity due to the potential for arbitrary code execution, though the requirement for user interaction prevents a critical rating.

Affected products

  • Adobe Illustrator 29.8.4 and earlier, 30.1 and earlier

Timeline

  • 2026-03-10: disclosed: CVE-2026-27267 published

References

Related threats