📦 Illustrator

by Adobe

🔍 What is Illustrator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21280

HIGH CVSS 8.6 Jan 13, 2026

This CVE describes an untrusted search path vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. Attackers can manipulate the search path to...

CVE-2025-61831

HIGH CVSS 7.8 Nov 11, 2025

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. Attackers could gain the same privileges as t...

CVE-2025-61820

HIGH CVSS 7.8 Nov 11, 2025

A heap-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This affects users running Illustrator versions 28.7.10, ...

CVE-2025-54283

HIGH CVSS 7.8 Oct 14, 2025

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. Attackers could gain control of the affected ...

CVE-2025-49564

HIGH CVSS 7.8 Aug 12, 2025

A stack-based buffer overflow vulnerability in Adobe Illustrator allows arbitrary code execution when a user opens a malicious file. This affects Illustrator versions 28.7.8, 29.6.1 and earlier. Attac...

CVE-2025-49532

HIGH CVSS 7.8 Jul 8, 2025

This CVE describes an integer underflow vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. It affects Illustrator versions 28.7.6, 29.5.1,...

CVE-2025-49526

HIGH CVSS 7.8 Jul 8, 2025

Adobe Illustrator versions 28.7.6, 29.5.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users ...

CVE-2025-49528

HIGH CVSS 7.8 Jul 8, 2025

A stack-based buffer overflow vulnerability in Adobe Illustrator allows arbitrary code execution when a user opens a malicious file. This affects Illustrator versions 28.7.6, 29.5.1 and earlier. Attac...

CVE-2025-49530

HIGH CVSS 7.8 Jul 8, 2025

Adobe Illustrator versions 28.7.6, 29.5.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users ...

CVE-2025-30330

HIGH CVSS 7.8 May 13, 2025

A heap-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This affects users running Illustrator versions 29.3, 28....

CVE-2025-21160

HIGH CVSS 7.8 Feb 11, 2025

Adobe Illustrator versions 29.1, 28.7.3 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users runn...

CVE-2025-21163

HIGH CVSS 7.8 Feb 11, 2025

A stack-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This affects users running Illustrator versions 29.1, 28...

CVE-2025-21159

HIGH CVSS 7.8 Feb 11, 2025

Adobe Illustrator versions 29.1, 28.7.3 and earlier contain a use-after-free vulnerability that could allow attackers to execute arbitrary code when a user opens a malicious file. This affects all use...

CVE-2024-49538

HIGH CVSS 7.8 Dec 10, 2024

Adobe Illustrator versions 29.0.0, 28.7.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a victim's system. This requires user interac...

CVE-2024-47452

HIGH CVSS 7.8 Nov 12, 2024

Adobe Illustrator versions 28.7.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when a user opens a malicious file. This affects all use...

CVE-2024-47450

HIGH CVSS 7.8 Nov 12, 2024

Adobe Illustrator versions 28.7.1 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users ru...

CVE-2024-41857

HIGH CVSS 7.8 Sep 13, 2024

Adobe Illustrator versions 28.6, 27.9.5 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users runn...

CVE-2024-34121

HIGH CVSS 7.8 Sep 13, 2024

Adobe Illustrator versions 28.6, 27.9.5 and earlier contain an integer overflow vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users runni...

CVE-2024-41856

HIGH CVSS 7.8 Aug 14, 2024

Adobe Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier contain an improper input validation vulnerability that could allow arbitrary code execution when a user opens a malicious file. This ...

CVE-2024-34133

HIGH CVSS 7.8 Aug 14, 2024

Adobe Illustrator versions 28.5, 27.9.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a victim's system. This affects users who open ...

CVE-2024-20792

HIGH CVSS 7.8 May 16, 2024

This CVE describes a Use After Free vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. The vulnerability affects Illustrator versions 28.4...

CVE-2024-30271

HIGH CVSS 7.8 Apr 11, 2024

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. Attackers could exploit this to run code with...

CVE-2024-30273

HIGH CVSS 7.8 Apr 11, 2024

A stack-based buffer overflow vulnerability in Adobe Illustrator allows arbitrary code execution when a user opens a malicious file. This affects users running vulnerable versions of Illustrator, pote...

CVE-2023-47074

HIGH CVSS 7.8 Dec 13, 2023

Adobe Illustrator versions 28.0 and earlier (and 27.9 and earlier) contain an out-of-bounds read vulnerability when parsing malicious files. This could allow an attacker to execute arbitrary code with...

CVE-2022-30646

HIGH CVSS 7.8 Sep 7, 2023

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. Attackers could gain control of the affected ...

CVE-2022-30642

HIGH CVSS 7.8 Sep 7, 2023

CVE-2022-30642 is an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. This affects users of Adobe Illustrator versio...

CVE-2022-30644

HIGH CVSS 7.8 Sep 7, 2023

This CVE describes a use-after-free vulnerability in Adobe Illustrator that could allow an attacker to execute arbitrary code on a victim's system. The vulnerability affects users of Adobe Illustrator...

CVE-2023-25859

HIGH CVSS 7.8 Mar 22, 2023

CVE-2023-25859 is an improper input validation vulnerability in Adobe Illustrator that allows arbitrary code execution when a user opens a malicious file. This affects Illustrator users on versions 26...

CVE-2023-25861

HIGH CVSS 7.8 Mar 22, 2023

CVE-2023-25861 is an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. This affects Illustrator versions 26.5.2 and e...

CVE-2022-30647

HIGH CVSS 7.8 Jun 15, 2022

CVE-2022-30647 is a use-after-free vulnerability in Adobe Illustrator that could allow an attacker to execute arbitrary code on a victim's system when they open a malicious file. This affects users of...

CVE-2022-30649

HIGH CVSS 7.8 Jun 15, 2022

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow an attacker to execute arbitrary code on a victim's system. The vulnerability affects users of Adobe Illus...

CVE-2022-23187

HIGH CVSS 7.8 Mar 11, 2022

Adobe Illustrator versions 26.0.3 and earlier contain a buffer overflow vulnerability that allows arbitrary code execution when a user opens a maliciously crafted file. This affects all users running ...

CVE-2022-23188

HIGH CVSS 7.8 Feb 16, 2022

Adobe Illustrator versions 25.4.3 and earlier and 26.0.2 and earlier contain a buffer overflow vulnerability when processing malicious files. This could allow attackers to execute arbitrary code with ...

CVE-2021-21104

HIGH CVSS 8.8 Sep 8, 2021

CVE-2021-21104 is a memory corruption vulnerability in Adobe Illustrator that allows remote code execution when a user opens a malicious file. Attackers can execute arbitrary code with the privileges ...

CVE-2021-36009

HIGH CVSS 7.8 Aug 20, 2021

CVE-2021-36009 is a memory corruption vulnerability in Adobe Illustrator that allows arbitrary code execution when a user opens a malicious file. Attackers can exploit this to run code with the victim...

CVE-2021-36011

HIGH CVSS 8.3 Aug 20, 2021

CVE-2021-36011 is a command injection vulnerability in Adobe Illustrator that allows arbitrary code execution when chained with a JavaScript debugging tool. Attackers can exploit this by tricking user...

CVE-2021-28591

HIGH CVSS 7.8 Aug 20, 2021

CVE-2021-28591 is an out-of-bounds write vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Attackers can exploit this to run code with the victim...

CVE-2021-21102

HIGH CVSS 8.8 Jun 28, 2021

CVE-2021-21102 is a path traversal vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Attackers can exploit this to run code with the victim's use...

CVE-2026-21288

MEDIUM CVSS 5.5 Jan 13, 2026

Adobe Illustrator versions 29.8.3, 30.0 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. This...

CVE-2025-49568

MEDIUM CVSS 5.5 Aug 12, 2025

Adobe Illustrator versions 28.7.8, 29.6.1 and earlier contain a use-after-free vulnerability that could allow attackers to read sensitive memory contents. This affects users who open malicious Illustr...

CVE-2025-49524

MEDIUM CVSS 5.5 Jul 8, 2025

Adobe Illustrator versions 28.7.6, 29.5.1 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. Th...

CVE-2024-47456

MEDIUM CVSS 5.5 Nov 12, 2024

Adobe Illustrator versions 28.7.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. This could potentially bypass security mitigatio...

CVE-2024-47454

MEDIUM CVSS 5.5 Nov 12, 2024

Adobe Illustrator versions 28.7.1 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. This could potentially bypass security mitigatio...

CVE-2024-43759

MEDIUM CVSS 5.5 Sep 13, 2024

Adobe Illustrator versions 28.6, 27.9.5 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. This...

CVE-2024-34135

MEDIUM CVSS 5.5 Aug 14, 2024

Adobe Illustrator versions 28.5, 27.9.4 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files. This could...

CVE-2024-34137

MEDIUM CVSS 5.5 Aug 14, 2024

Adobe Illustrator versions 28.5, 27.9.4 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. This...