Skip to content
Threat Feed
high threat exploited

Critical Remote Code Execution Vulnerabilities in Adobe Illustrator

Three vulnerabilities in Adobe Illustrator allow for remote code execution when a user opens a maliciously crafted file, potentially granting an attacker full control over the host system.

On September 10, 2026, the NCSC-NL published an alert regarding three high-severity vulnerabilities found in Adobe Illustrator. These vulnerabilities, carrying CVSS scores between 7.8 and 8.6, enable an attacker to achieve arbitrary code execution on a target system. The primary vector for exploitation is the delivery of a specially crafted file to a victim. When the victim opens the malicious file within Adobe Illustrator, the application processes the malformed data in a way that triggers code execution under the context of the user running the application.

If successfully exploited, an attacker could gain complete control over the affected workstation. This includes the ability to view, modify, or delete files, as well as the capacity to install further malicious software, such as infostealers, backdoors, or ransomware. There is no evidence at this time of active, in-the-wild exploitation. Adobe has released security updates to patch these flaws, and immediate deployment is recommended to mitigate the risk of compromise.

Impact

Successful exploitation allows an attacker to gain unauthorized access to the victim's machine. The impact includes full compromise of the user's data, potential exfiltration of sensitive information, and the persistence of further malware on the target system. These vulnerabilities pose a significant risk to organizations where users frequently handle external graphics files, as the attack requires minimal interaction beyond opening a file.

Recommendation

  • Immediately apply the security updates provided by Adobe for the affected Illustrator versions.
  • Coordinate with internal IT departments to verify software versions and ensure patch deployment is completed across all endpoints.
  • Monitor endpoint telemetry for unusual child processes spawned by Illustrator (e.g., cmd.exe, powershell.exe, wscript.exe) following the opening of document files.

Immediate actions

Deploy latest Adobe security updates across all instances of Illustrator.

IT Operations 24h

Threat Hunt

Search for suspicious child processes originating from Illustrator.exe or Illustrator process tree.

T1204.002 medium medium confidence hunt now

Data: Process creation logs

Mitigations

Install latest security updates from Adobe.

immediate IT Operations

Adobe Illustrator vulnerabilities