
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27270 is an Out-of-bounds Read vulnerability (CWE-125) in Adobe Illustrator that could lead to memory disclosure. It affects Illustrator versions 29.8.4 and earlier (29.x branch) and 30.1 and earlier (30.x branch). The vulnerability was disclosed on March 10, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), where Illustrator fails to properly validate memory boundaries when processing file content, allowing reads beyond allocated buffer limits. An attacker exploits this by crafting a malicious file (e.g., a specially structured Illustrator document) that, when opened by a victim, triggers the out-of-bounds read and exposes contents of application memory. The attack vector is local, requires no privileges, but does require user interaction — specifically, a victim must open the malicious file. No public proof-of-concept exploit code has been identified (Adobe Advisory, Feedly).
Successful exploitation results in memory disclosure, exposing sensitive information stored in the Illustrator process's memory space to the attacker. There is no impact on integrity or availability — the vulnerability is limited to a confidentiality breach. The scope is unchanged, meaning the impact is confined to the vulnerable application itself, with no direct path to lateral movement or privilege escalation from this vulnerability alone (Adobe Advisory, Feedly).
.ai or compatible format) that triggers an out-of-bounds read when parsed by Illustrator's file processing routines.Adobe has released patched versions addressing this vulnerability: update to Illustrator 29.8.5 or later (for the 29.x branch) or 30.2 or later (for the 30.x branch). Until patching is feasible, organizations should restrict users from opening Illustrator files received from untrusted or external sources, and implement file-type filtering at email and web gateways. Tenable Nessus plugin 301722 is available for detection of vulnerable installations (Adobe Advisory, Tenable).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution or information disclosure, recommending prompt patching (CIS Advisory). Spain's INCIBE-CERT also published an alert for this CVE. No significant researcher commentary or social media discussion has been observed beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."