Junglewise Threat Intelligence

CVE-2026-75990: Adobe Illustrator incorrect authorization arbitrary code execution

CVE-2026-75990 · Severity: high · CVSS 8.6 · Published 2026-09-08

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator contains an authorization flaw that allows attackers to execute arbitrary code with the privileges of the user running the application. An attacker can exploit this by tricking a user into opening a malicious file, potentially leading to data theft, system compromise, or further attacks on the victim's machine.

Technical details

The vulnerability is an incorrect authorization issue in Adobe Illustrator that permits arbitrary code execution in the context of the current user. The flaw requires user interaction—specifically, a victim must open a malicious file—to be exploited. The change in scope (from Changed to ScopeChanged in CVSS terms) indicates the vulnerability can affect resources beyond the vulnerable component itself. No patch information is currently available from the provided advisory content.

Affected products

  • Adobe Illustrator

Timeline

  • 2026-09-08: disclosed

References

Related threats