
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75991 is an Improper Input Validation vulnerability (CWE-20) in Adobe Illustrator that can result in arbitrary code execution in the context of the current user. It affects Adobe Illustrator Desktop 2025 (versions 29.0 through 29.8.10) and Adobe Illustrator Desktop 2026 (versions 30.0 through 30.7). The vulnerability was published on September 8, 2026, with patches released by Adobe under security bulletin APSB26-131. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability stems from insufficient input validation when Adobe Illustrator processes certain file types, classified under CWE-20 (Improper Input Validation). The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted malicious file. The scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself. No public proof-of-concept code has been identified at this time (GitHub Advisory, Adobe Advisory).
Successful exploitation grants an attacker high confidentiality, integrity, and availability impact, effectively allowing full control over the affected system in the context of the current user. Because the scope is changed, the impact can extend beyond the Illustrator process itself to other system resources. An attacker could read sensitive files, modify data, install malware, or disrupt application availability on the compromised host (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-75991 as of the time of this report. The EPSS score is approximately 0.217% (12th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and the attack as not automatable (GitHub Advisory).
cmd.exe, powershell.exe, bash, curl, wget) following the opening of an Illustrator file.%APPDATA%, %TEMP%, or /tmp.Adobe has released patched versions addressing this vulnerability: Illustrator Desktop 2025 version 29.8.11 and Illustrator Desktop 2026 version 30.8. Users should update immediately via the Creative Cloud desktop application or Adobe's update mechanism. As a general precaution prior to patching, users should avoid opening Illustrator files from untrusted or unknown sources (Adobe Advisory, GitHub Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Tenable published a Nessus detection plugin (ID 343840) for this vulnerability shortly after disclosure. AusCERT also issued a bulletin (ESB-2026.10692) to notify its constituency. No significant social media controversy or notable researcher commentary beyond standard patch advisories has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."