Adobe Illustrator patches three code-execution flaws
Adobe fixed three Illustrator vulnerabilities that let attackers run arbitrary code via malicious files, patches available.
NCSC-NL published an advisory summarizing three vulnerabilities patched by Adobe in Illustrator, all related to file-handling mechanisms. CVE-2026-75990 involves incorrect authorization allowing arbitrary code execution when a user opens a malicious file. CVE-2026-75991 relates to improper input validation, also enabling code execution via specially crafted files. CVE-2026-75992 is an out-of-bounds write that occurs during processing of certain file input, allowing memory corruption and arbitrary code execution when a malicious file is opened.
All three vulnerabilities require user interaction (opening a crafted file) and carry high CVSS v3 scores (8.6, 8.6, and 7.8 respectively), indicating significant impact but not remote/network exploitation without user action. No in-the-wild exploitation is mentioned in the advisory. Defenders should prioritize applying Adobe's released updates for Illustrator and exercise caution with untrusted Illustrator files, particularly in workflows where files are received from external sources (e.g., design agencies, print vendors, freelance contributors).
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0364.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free