Junglewise Threat Intelligence

CVE-2026-27270: Adobe Illustrator out-of-bounds read in memory handling

CVE-2026-27270 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator, a widely-used professional graphics design tool, contains a vulnerability that allows attackers to read sensitive data from memory when a user opens a malicious file. This could expose confidential information such as credentials, design files, or other data temporarily held in memory during file processing.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in Illustrator's file parsing logic. An attacker can craft a malicious Illustrator document that, when opened by a victim, triggers an out-of-bounds memory access, allowing unauthorized reading of adjacent memory contents. This requires user interaction (opening a file) to trigger. The vulnerability affects versions 29.8.4 and 30.1 and earlier. No patch information is currently available in the advisory text.

Affected products

  • Adobe Illustrator 29.8.4, 30.1 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats