
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21333 is an Untrusted Search Path vulnerability (CWE-426) in Adobe Illustrator that allows attackers to execute arbitrary code in the context of the current user. Affected versions include Illustrator 29.8.4, 30.1, and all earlier releases in the 29.x and 30.x branches. Adobe disclosed and patched the vulnerability on March 10, 2026, as part of its March 2026 security update cycle. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning Illustrator searches for resources — such as DLLs or executables — in directories that an attacker can control, enabling DLL hijacking or binary planting attacks. The attack vector is local, requiring no privileges, but does require user interaction: a victim must open a specially crafted malicious file. When the file is opened, Illustrator resolves a dependency or resource from an attacker-controlled path, loading and executing the malicious payload. This maps to MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) (Adobe Advisory, Feedly).
Successful exploitation grants an attacker arbitrary code execution with the privileges of the user running Adobe Illustrator, resulting in high impact to confidentiality, integrity, and availability. The CVSS scope is marked as "Changed," indicating the vulnerability can affect resources beyond the Illustrator process itself, potentially enabling data theft, file modification, and system disruption. An attacker could leverage this foothold for further lateral movement within the victim's environment (Adobe Advisory, Feedly).
.ai, .eps, or .pdf) that, when opened, triggers Illustrator to search for a DLL or executable in an attacker-controlled directory.%APPDATA%, %TEMP%, or Illustrator installation directories.cmd.exe, powershell.exe, curl.exe, or unknown executables); Illustrator loading DLLs from non-standard or user-writable directories (detectable via process monitoring tools like Sysmon or Process Monitor).Adobe has released patched versions: Illustrator 29.8.5 (for the 29.x branch) and Illustrator 30.2 (for the 30.x branch). Users should update immediately via the Creative Cloud desktop application. As a precautionary measure, users should avoid opening Illustrator files received from untrusted or unknown sources. Organizations may also consider restricting Illustrator usage to files from verified, trusted sources and monitoring for DLL loading from non-standard paths (Adobe Advisory, CIS Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple Adobe product vulnerabilities disclosed in March 2026, including this one, could allow arbitrary code execution (CIS Advisory). The Hacker Wire published a brief write-up on the vulnerability highlighting the untrusted search path mechanism (The Hacker Wire). General community sentiment treats this as a moderate-priority patch given the lack of active exploitation, though the high CVSS score and scope change warrant prompt remediation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."