Junglewise Threat Intelligence

CVE-2026-34618: Adobe Illustrator out-of-bounds write in file processing

CVE-2026-34618 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator, a professional graphic design application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious file. Successful exploitation could lead to unauthorized software installation, data theft, or complete system compromise under the permissions of the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Illustrator versions 30.2, 29.8.5 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. The attack vector is local, requiring the victim to manually open a malicious file (User Interaction: Required). Adobe has addressed this in newer versions, and users are advised to update to Illustrator 30.3 or 29.8.6 and later.

Affected products

  • Adobe Illustrator 30.2, 29.8.5 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe security bulletin APSB26-42 published

References

Related threats