Adobe Illustrator vulnerabilities
178 known vulnerabilities affecting adobe/illustrator.
Total CVEs
178
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH105MEDIUM58LOW1
Vulnerabilities
Page 2 of 9
CVE-2012-2025P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-09
CVE-2012-2025 [CRITICAL] CVE-2012-2025: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
nvd
CVE-2025-61820P3HIGHCVSS 7.8≥ 28.0, ≤ 28.7.10≥ 29.0, < 29.8.3+1 more2025-11-11
CVE-2025-61820 [HIGH] CWE-122 CVE-2025-61820: Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulner
Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-61831P3HIGHCVSS 7.8≥ 28.0, ≤ 28.7.10≥ 29.0, < 29.8.3+1 more2025-11-11
CVE-2025-61831 [HIGH] CWE-787 CVE-2025-61831: Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerabilit
Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54283P3HIGHCVSS 7.8≥ 28.0, < 28.7.10≥ 29.0, < 29.8+1 more2025-10-14
CVE-2025-54283 [HIGH] CWE-787 CVE-2025-54283: Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54284P3HIGHCVSS 7.8≥ 28.0, < 28.7.10≥ 29.0, < 29.8+1 more2025-10-14
CVE-2025-54284 [HIGH] CWE-787 CVE-2025-54284: Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-34661P3HIGHCVSS 7.8≥ 29.0, < 29.8.7≥ 30.0, < 30.4+1 more2026-05-12
CVE-2026-34661 [HIGH] CWE-787 CVE-2026-34661: Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-21362P3HIGHCVSS 7.8≥ 29.0, < 29.8.5≥ 30.0, < 30.2+1 more2026-03-10
CVE-2026-21362 [HIGH] CWE-787 CVE-2026-21362: Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48337P3HIGHCVSS 7.8≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48337 [HIGH] CWE-787 CVE-2026-48337: Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48335P3HIGHCVSS 7.8≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48335 [HIGH] CWE-787 CVE-2026-48335: Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48336P3HIGHCVSS 7.8≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48336 [HIGH] CWE-787 CVE-2026-48336: Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-27272P3HIGHCVSS 7.8≥ 29.0, < 29.8.5≥ 30.0, < 30.2+1 more2026-03-10
CVE-2026-27272 [HIGH] CWE-787 CVE-2026-27272: Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-23188P3HIGHCVSS 7.8≤ 25.4.3≥ 26.0.0, ≤ 26.0.2+1 more2022-02-16
CVE-2022-23188 [HIGH] CWE-120 CVE-2022-23188: Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer ov
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted malicious file i
nvd
CVE-2021-21054P3HIGHCVSS 7.8≤ 25.1≥ unspecified, ≤ 25.12021-02-11
CVE-2021-21054 [HIGH] CWE-787 CVE-2021-21054: Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability whe
Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious f
nvd
CVE-2022-23186P3HIGHCVSS 7.8≤ 25.4.3≥ 26.0.0, ≤ 26.0.2+1 more2022-02-16
CVE-2022-23186 [HIGH] CWE-787 CVE-2022-23186: Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-b
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-30649P3HIGHCVSS 7.8≤ 25.4.5≥ 26.0, ≤ 26.0.2+1 more2022-06-15
CVE-2022-30649 [HIGH] CWE-787 CVE-2022-30649: Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-b
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49564P3HIGHCVSS 7.8≥ 28.0, < 28.7.9≥ 29.0, < 29.7+1 more2025-08-12
CVE-2025-49564 [HIGH] CWE-121 CVE-2025-49564: Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulner
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49563P3HIGHCVSS 7.8≥ 28.0, < 28.7.9≥ 29.0, < 29.7+1 more2025-08-12
CVE-2025-49563 [HIGH] CWE-787 CVE-2025-49563: Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49526P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49526 [HIGH] CWE-787 CVE-2025-49526: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49530P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49530 [HIGH] CWE-787 CVE-2025-49530: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-27267P3HIGHCVSS 7.8≥ 29.0, < 29.8.5≥ 30.0, < 30.2+1 more2026-03-10
CVE-2026-27267 [HIGH] CWE-121 CVE-2026-27267: Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerab
Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd