Junglewise Threat Intelligence

CVE-2026-34687: Adobe Illustrator heap buffer overflow

CVE-2026-34687 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator, a professional graphic design application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software installation, data theft, or complete system compromise in the context of the logged-in user.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe Illustrator versions 29.8.6, 30.3 and earlier. The vulnerability is triggered when the application improperly handles memory during the parsing of a specially crafted file. An attacker can achieve arbitrary code execution in the context of the current user by convincing a victim to open a malicious document. The attack vector is local (file-based) and requires user interaction. Adobe has addressed this in updated versions of the software.

Affected products

  • Adobe Illustrator 29.8.6 and earlier, 30.3 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats