
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71441 is an out-of-bounds read vulnerability (CWE-125) in Adobe Illustrator that can lead to disclosure of sensitive memory contents. An unauthenticated attacker can exploit this by tricking a victim into opening a specially crafted malicious file. Affected versions include Adobe Illustrator Desktop 2025 (versions 29.0–29.8.9) and Adobe Illustrator Desktop 2026 (versions 30.0–30.6). The vulnerability was published on August 25, 2026, with patches released by September 8, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring when Illustrator processes a maliciously crafted file and reads data beyond the intended buffer boundary, exposing sensitive memory contents. The attack vector is local, requiring no privileges but necessitating user interaction — specifically, a victim must open a malicious file (e.g., a crafted AI, PDF, or other Illustrator-supported format). Attack complexity is low, meaning no special conditions or race conditions are required beyond delivering the malicious file to the target. No public proof-of-concept code has been identified at this time (GitHub Advisory, Adobe Advisory).
Successful exploitation results in high confidentiality impact, as sensitive data from the application's memory can be disclosed to the attacker. Integrity and availability are not affected by this vulnerability. The primary risk is memory disclosure, which could expose sensitive information such as credentials, cryptographic keys, or other in-memory data processed by Illustrator, potentially enabling further attacks (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-71441. The EPSS score is approximately 0.155%, indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment notes exploitation as "none" and the vulnerability as not automatable (GitHub Advisory).
.ai, .eps, .pdf, .svg) received via email or downloaded from untrusted sources.Illustrator.exe) crashing or generating unexpected error dialogs when opening specific files, which may indicate attempted exploitation.Adobe has released patched versions addressing this vulnerability: Illustrator Desktop 2025 version 29.8.10 and Illustrator Desktop 2026 version 30.7. Users should update immediately via the Creative Cloud desktop application. As a workaround, users should avoid opening Illustrator files from untrusted or unknown sources, and organizations should consider restricting file sources to trusted locations or implementing application whitelisting (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."