# Adobe Illustrator patches three code-execution flaws

Published: 2026-09-09 · Severity: routine · Sectors: technology, media
Canonical: https://vorant.io/reports/b778c027-8202-5756-82c8-95341d3dbbb8/adobe-illustrator-patches-three-code-execution-flaws

> Adobe fixed three Illustrator vulnerabilities that let attackers run arbitrary code via malicious files, patches available.

NCSC-NL published an advisory summarizing three vulnerabilities patched by Adobe in Illustrator, all related to file-handling mechanisms. CVE-2026-75990 involves incorrect authorization allowing arbitrary code execution when a user opens a malicious file. CVE-2026-75991 relates to improper input validation, also enabling code execution via specially crafted files. CVE-2026-75992 is an out-of-bounds write that occurs during processing of certain file input, allowing memory corruption and arbitrary code execution when a malicious file is opened.

All three vulnerabilities require user interaction (opening a crafted file) and carry high CVSS v3 scores (8.6, 8.6, and 7.8 respectively), indicating significant impact but not remote/network exploitation without user action. No in-the-wild exploitation is mentioned in the advisory. Defenders should prioritize applying Adobe's released updates for Illustrator and exercise caution with untrusted Illustrator files, particularly in workflows where files are received from external sources (e.g., design agencies, print vendors, freelance contributors).

## Mentioned in this report

- Vulnerabilities: CVE-2026-75990, CVE-2026-75991, CVE-2026-75992

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0364.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b778c027-8202-5756-82c8-95341d3dbbb8/adobe-illustrator-patches-three-code-execution-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
