Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75990
Adobe Illustrator vulnerability analysis and mitigation

Overview

CVE-2026-75990 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Illustrator that can result in arbitrary code execution in the context of the current user. The vulnerability affects Adobe Illustrator Desktop 2025 (versions up to and including 29.8.10) and Adobe Illustrator Desktop 2026 (versions up to and including 30.7). It was published on September 8, 2026, with a patch made available shortly after. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization), meaning Adobe Illustrator fails to correctly perform authorization checks when processing certain file content, allowing unauthorized actions to occur. The attack vector is local — an attacker must deliver a specially crafted malicious file to the victim, who must then open it in Illustrator. No privileges are required on the part of the attacker, but user interaction is mandatory. Notably, the scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact. Because the scope is changed, the exploitation can affect resources or components beyond the Illustrator application itself, potentially enabling further access to the underlying system. Data exposure, file system manipulation, and persistence mechanisms are all plausible consequences depending on the privileges of the targeted user (GitHub Advisory).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.2%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Exploitation requires user interaction, which reduces the likelihood of automated or mass exploitation.

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted Adobe Illustrator file (e.g., .ai, .eps, or other supported format) that exploits the incorrect authorization logic when parsed by Illustrator.
  2. Deliver the file to the victim: The attacker distributes the malicious file via phishing email, malicious download link, shared network drive, or other social engineering methods.
  3. Victim opens the file: The targeted user opens the malicious file in a vulnerable version of Adobe Illustrator Desktop 2025 (≤29.8.10) or Desktop 2026 (≤30.7).
  4. Trigger the vulnerability: Upon parsing the file, Illustrator's authorization check fails, allowing the embedded malicious content to execute arbitrary code in the context of the current user.
  5. Achieve code execution: The attacker's payload runs with the victim's privileges, potentially enabling data theft, malware installation, persistence, or lateral movement within the environment (GitHub Advisory, Adobe Advisory).

Indicators of compromise

  • File System: Unexpected files created in user-writable directories (e.g., %APPDATA%, %TEMP%, or /tmp) shortly after opening an Illustrator file; new or modified startup/persistence entries (registry run keys on Windows, LaunchAgents on macOS).
  • Process: Unusual child processes spawned by the Illustrator process (e.g., cmd.exe, powershell.exe, bash, curl, wget); unexpected network connections initiated by the Illustrator process.
  • Network: Outbound connections from the Illustrator process to unknown or suspicious external IP addresses or domains following file open events.
  • Logs: Application crash logs or error entries in Illustrator logs coinciding with the opening of an untrusted file; OS audit logs showing process creation events parented to Illustrator.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Illustrator Desktop 2025 version 29.8.11 and Illustrator Desktop 2026 version 30.8. Users should update to these versions immediately via the Creative Cloud desktop application or Adobe's update mechanism. As a general precaution, users should avoid opening Illustrator files received from untrusted or unknown sources, and organizations may consider implementing application whitelisting or file execution policies to reduce risk (Adobe Advisory, GitHub Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). Tenable published a Nessus detection plugin (ID 343840) for this vulnerability, enabling automated scanning of affected systems. No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability tracking and advisory coverage.

Additional resources


SourceThis report was generated using AI

Related Adobe Illustrator vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75991HIGH8.6
  • Adobe Illustrator logoAdobe Illustrator
  • cpe:2.3:a:adobe:illustrator
NoYesSep 08, 2026
CVE-2026-75990HIGH8.6
  • Adobe Illustrator logoAdobe Illustrator
  • cpe:2.3:a:adobe:illustrator
NoYesSep 08, 2026
CVE-2026-75992HIGH7.8
  • Adobe Illustrator logoAdobe Illustrator
  • cpe:2.3:a:adobe:illustrator
NoYesSep 08, 2026
CVE-2026-48337HIGH7.8
  • Adobe Illustrator logoAdobe Illustrator
  • cpe:2.3:a:adobe:illustrator
NoYesJul 14, 2026
CVE-2026-71441MEDIUM5.5
  • Adobe Illustrator logoAdobe Illustrator
  • cpe:2.3:a:adobe:illustrator
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management