Adobe Illustrator Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A vulnerability allowing out-of-bounds write has been identified in Adobe Illustrator. This issue could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file. The vulnerability affects Adobe Illustrator 2025 versions through 29.8.7 and Adobe Illustrator 2026 versions through 30.5, both on Windows.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, allowing an attacker to execute malicious code on the affected system with the privileges of the user running Illustrator.

Remediation

Users are advised to update Adobe Illustrator to version 29.8.9 for the 2025 release or version 30.6 for the 2026 release. The update can be downloaded via the Creative Cloud desktop app or through the Adobe Products Catalog Download Page.

Added: Jul 15, 2026, 3:50 AM
Updated: Jul 15, 2026, 3:50 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
3.6
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.