
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27268 is an Out-of-bounds Read vulnerability (CWE-125) in Adobe Illustrator that could lead to memory exposure and disclosure of sensitive information. It affects Illustrator versions 29.0–29.8.4 and 30.0–30.1 (and earlier within those ranges). Adobe disclosed and patched this vulnerability on March 10, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), where Illustrator reads data beyond the bounds of an allocated memory buffer when processing a specially crafted file. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a malicious file in Illustrator. Successful exploitation allows an attacker to read sensitive contents from process memory, potentially exposing credentials, keys, or other in-memory data (Adobe Advisory).
Exploitation of this vulnerability results in a high confidentiality impact, with no effect on integrity or availability. An unauthenticated attacker who can trick a user into opening a crafted file can read sensitive information from Illustrator's process memory, which may include application data, credentials, or other confidential content loaded at runtime. The scope is limited to the affected host and process (Adobe Advisory).
.ai, .eps, .pdf, .svg) received via email or downloaded from untrusted sources.Adobe has released patched versions to address this vulnerability: users should update to Illustrator 29.8.5 or later (for the 29.x branch) or 30.2 or later (for the 30.x branch). As an interim workaround, users should avoid opening Illustrator files from untrusted or unknown sources. Organizations should consider restricting file sharing from external sources until patching is complete (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in March 2026, including this issue, flagging potential for arbitrary code execution across the Adobe product suite (CIS Advisory). Community reaction has been minimal given the medium severity and lack of active exploitation, with standard tracking across vulnerability databases and automated feeds.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."