CVE-2026-27268
published 2026-03-10CVE-2026-27268: Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.14%
4.2th percentile
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | illustrator | <= 30.1 | — |
| adobe | illustrator | >= 29.0 < 29.8.5 | 29.8.5 |
| adobe | illustrator | >= 30.0 < 30.2 | 30.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21288 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21288 [MEDIUM] CVE-2026-21288 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21288 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published January 13, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:il
Wiz
CVE-2026-27270 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27270 [HIGH] CVE-2026-27270 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27270 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows
Wiz
CVE-2026-21333 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21333 [HIGH] CVE-2026-21333 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21333 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 8.6
Score
Published March 10, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows Severity HIGH Has Fix Added at: Mar 12, 20
Wiz
CVE-2026-27272 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27272 [HIGH] CVE-2026-27272 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27272 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows Severity HIGH Has Fix Added at: Mar 12, 2026
Windo
Wiz
CVE-2026-27271 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27271 [HIGH] CVE-2026-27271 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27271 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows Severity HIGH Has Fix Added at: Mar 12, 2026
Wiz
CVE-2026-27267 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27267 [HIGH] CVE-2026-27267 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27267 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows Severity HIGH Has Fix Added at: Mar 12, 2026
Wiz
CVE-2026-27268 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27268 [HIGH] CVE-2026-27268 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27268 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows
Wiz
CVE-2026-21280 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-21280 [HIGH] CVE-2026-21280 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21280 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Source : NVD
## 8.6
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CI
Wiz
CVE-2026-21362 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21362 [HIGH] CVE-2026-21362 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21362 :
Adobe Illustrator vulnerability analysis and mitigation
Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Illustrator
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:illustrator
Sources
Windows Severity HIGH Has Fix Added at: Mar 12, 2026
Windo
2026-03-10
Published