Critical Remote Code Execution Vulnerabilities in Adobe Illustrator
Three vulnerabilities in Adobe Illustrator allow for remote code execution when a user opens a maliciously crafted file, potentially granting an attacker full control over the host system.
On September 10, 2026, the NCSC-NL published an alert regarding three high-severity vulnerabilities found in Adobe Illustrator. These vulnerabilities, carrying CVSS scores between 7.8 and 8.6, enable an attacker to achieve arbitrary code execution on a target system. The primary vector for exploitation is the delivery of a specially crafted file to a victim. When the victim opens the malicious file within Adobe Illustrator, the application processes the malformed data in a way that triggers code execution under the context of the user running the application.
If successfully exploited, an attacker could gain complete control over the affected workstation. This includes the ability to view, modify, or delete files, as well as the capacity to install further malicious software, such as infostealers, backdoors, or ransomware. There is no evidence at this time of active, in-the-wild exploitation. Adobe has released security updates to patch these flaws, and immediate deployment is recommended to mitigate the risk of compromise.
Impact
Successful exploitation allows an attacker to gain unauthorized access to the victim's machine. The impact includes full compromise of the user's data, potential exfiltration of sensitive information, and the persistence of further malware on the target system. These vulnerabilities pose a significant risk to organizations where users frequently handle external graphics files, as the attack requires minimal interaction beyond opening a file.
Recommendation
- Immediately apply the security updates provided by Adobe for the affected Illustrator versions.
- Coordinate with internal IT departments to verify software versions and ensure patch deployment is completed across all endpoints.
- Monitor endpoint telemetry for unusual child processes spawned by Illustrator (e.g., cmd.exe, powershell.exe, wscript.exe) following the opening of document files.
Immediate actions
Deploy latest Adobe security updates across all instances of Illustrator.
Threat Hunt
Search for suspicious child processes originating from Illustrator.exe or Illustrator process tree.
Data: Process creation logs
Mitigations
Install latest security updates from Adobe.
Adobe Illustrator vulnerabilities