CVE-2026-21333

8.6

Adobe · Illustrator

Adobe Illustrator is susceptible to an Untrusted Search Path vulnerability that may allow a local attacker to execute arbitrary code when a victim opens a specially crafted malicious file.

Executive summary

Adobe Illustrator is affected by a critical untrusted search path vulnerability that allows for arbitrary code execution upon opening a malicious file.

Vulnerability

This is an untrusted search path vulnerability (CWE-426) occurring when the application improperly handles file paths. Successful exploitation requires user interaction, as a victim must be enticed to open a malicious file, at which point the attacker can execute code in the context of the current user.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational security, as it allows attackers to gain unauthorized control over user workstations. Given the CVSS score of 8.6, this vulnerability is classified as High severity. Successful exploitation could lead to full system compromise, data exfiltration, or the deployment of secondary malware within the corporate network.

Remediation

Immediate Action: Update Adobe Illustrator Desktop 2026 to version 30.2 or later, and Adobe Illustrator Desktop 2025 to version 29.8.5 or later.

Proactive Monitoring: Monitor endpoint activity for suspicious file execution patterns or unauthorized process spawning originating from Adobe Illustrator.

Compensating Controls: Implement strict application control policies to prevent the execution of untrusted binaries and educate users to avoid opening files from untrusted or unknown sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a severe risk due to the potential for arbitrary code execution. Security teams should prioritize the deployment of the vendor-provided patches immediately to ensure all workstations are running the corrected versions. Failure to patch leaves systems vulnerable to malicious file-based attacks that can bypass standard security controls.

More Adobe CVEs

Sources