
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21280 is an Untrusted Search Path vulnerability (CWE-426) in Adobe Illustrator that allows arbitrary code execution in the context of the current user. Affected versions include Illustrator 29.8.3, 30.0, and earlier (specifically versions from 29.0 up to but excluding 29.8.4, and version 30.0), running on both Windows and macOS. The vulnerability was disclosed on January 13, 2026, with initial NVD analysis completed on January 14, 2026. It carries a CVSS v3.1 base score of 8.6 (High), assigned by Adobe Systems Incorporated (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-426 (Untrusted Search Path), mapped to CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) and MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable). When Adobe Illustrator searches for critical resources or programs using a configurable search path, an attacker can manipulate that path to point to a malicious executable, which Illustrator will then load and run. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted malicious file — and the vulnerability has a changed scope, meaning the impact can extend beyond the Illustrator process itself (Adobe Advisory, Feedly).
Successful exploitation results in arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. Because the scope is marked as changed, the effects can extend beyond the Illustrator application itself, potentially affecting other components or resources on the system. An attacker who tricks a user into opening a malicious file could gain the ability to read sensitive data, modify files, or disrupt system availability, and may use this foothold for further lateral movement within the environment (Adobe Advisory, Feedly).
.ai or .eps) that, when opened, triggers Illustrator to search for a resource or program using a manipulable search path..ai or .eps files, or in writable directories present early in the system or user PATH; newly created or modified files in Illustrator's working or plugin directories.cmd.exe, powershell.exe, bash, curl, or unknown executables); processes running under the user account with no clear user-initiated origin.Adobe has released patched versions to address this vulnerability: users should update Adobe Illustrator to version 29.8.4 or later (for the 29.x branch) or the next available release beyond 30.0. Updates can be applied via the Creative Cloud desktop application. As a general workaround, users should avoid opening Illustrator files from untrusted or unknown sources, and administrators should ensure that writable directories are not present early in the system PATH to reduce the risk of search path manipulation. Keeping all Adobe software current with the latest security patches is strongly recommended (Adobe Advisory, CIS Advisory).
The vulnerability was covered in the Zero Day Initiative's January 2026 Security Update Review, which noted it as part of Adobe's broader January patch release (Beyond Machines). The Center for Internet Security (CIS) issued an advisory noting that multiple Adobe vulnerabilities disclosed in January 2026, including this one, could allow arbitrary code execution (CIS Advisory). Social media coverage was limited, with brief mentions on Mastodon and Bluesky by security news accounts. Overall community reaction was measured, given the lack of active exploitation and the requirement for user interaction.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."