CVE-2026-34618
published 2026-04-14CVE-2026-34618: Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
8.2th percentile
Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | illustrator | <= 29.8.5 | — |
| adobe | illustrator | >= 29.0 < 29.8.6 | 29.8.6 |
| adobe | illustrator | >= 30.0 < 30.3 | 30.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wcxr-mjcf-c92c: Illustrator versions 30
ghsa_unreviewed·2026-04-14
CVE-2026-34618 [HIGH] CWE-787 GHSA-wcxr-mjcf-c92c: Illustrator versions 30
Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe Illustrator up to 29.8.5/30.2 File out-of-bounds write (apsb26-42)
vuldb·2026-04-14·CVSS 7.8
CVE-2026-34618 [HIGH] Adobe Illustrator up to 29.8.5/30.2 File out-of-bounds write (apsb26-42)
A vulnerability, which was classified as critical, has been found in Adobe Illustrator up to 29.8.5/30.2. Affected by this issue is some unknown functionality of the component File Handler. This manipulation causes out-of-bounds write.
The identification of this vulnerability is CVE-2026-34618. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published