
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21288 is a NULL Pointer Dereference vulnerability (CWE-476) in Adobe Illustrator that can cause application-level denial-of-service. It affects Illustrator versions 29.8.3, 30.0, and earlier (specifically versions from 29.0 up to but not including 29.8.4, and version 30.0) on both Windows and macOS. The vulnerability was disclosed on January 13, 2026, with an initial NVD analysis completed on January 14, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium), assigned by Adobe Systems Incorporated (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring when Adobe Illustrator processes a specially crafted malicious file. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction — specifically, a victim must open a malicious file. When the application attempts to dereference a null pointer during file parsing, it crashes, resulting in a denial-of-service condition. No public technical write-ups or proof-of-concept code detailing the specific file parsing routine involved have been identified (Adobe Advisory, Feedly).
Successful exploitation results in a crash of the Adobe Illustrator application, causing a denial-of-service for the affected user. There is no impact on confidentiality or integrity — only availability is affected (A:H). The scope is limited to the local user's session, with no evidence of lateral movement potential or data exposure risk, making this a moderate-severity disruption to creative workflows rather than a system-level compromise (Adobe Advisory, Feedly).
illustrator.exe process, particularly when opening files from external sources.Adobe has released patched versions addressing this vulnerability: Illustrator 29.8.4 (for the 29.x branch) and a fix for version 30.0 users. Users should update to Illustrator 29.8.4 or later via the Creative Cloud desktop application. As a workaround, users should avoid opening Illustrator files from untrusted or unknown sources, and organizations should implement file transfer controls to restrict potentially malicious file delivery. The CIS advisory also recommends applying the update as part of broader Adobe product patching (Adobe Advisory, CIS Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products, including CVE-2026-21288, as part of the January 2026 Adobe security update cycle (CIS Advisory). The Zero Day Initiative also covered the January 2026 security update review, which included this vulnerability (BeyondMachines). No significant independent researcher commentary or notable social media discussion has been identified for this moderate-severity issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."