PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75991 Adobe CVE debrief

CVE-2026-75991 is an Improper Input Validation vulnerability in Adobe Illustrator that could result in arbitrary code execution. User interaction is required to exploit this issue. The vulnerability affects Adobe Illustrator, potentially leading to code execution upon opening malicious files. This issue requires immediate attention from Adobe Illustrator users, particularly those in creative and design teams, to assess exposure and verify their versions. Exploitation of this issue requires user interaction, specifically opening a malicious file.

Vendor
Adobe
Product
Illustrator Desktop 2026
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-18
Advisory published
2026-09-08
Advisory updated
2026-09-18

Who should care

Adobe Illustrator users, particularly those in creative and design teams, should assess exposure and verify their versions. Users of Adobe Illustrator should prioritize updating to patched versions to prevent potential code execution. This vulnerability requires immediate attention from Adobe Illustrator users to assess exposure and verify their versions.

Why it matters

CVE-2026-75991 is a high-severity vulnerability in Adobe Illustrator that requires immediate attention. Users should verify their versions and update to patched releases to prevent potential code execution.

  • Potential arbitrary code execution upon opening malicious files.
  • Requires user interaction to exploit.
  • Scope change possible due to successful exploitation.

Technical summary

CVE-2026-75991 is an Improper Input Validation vulnerability in Adobe Illustrator that could result in arbitrary code execution. Exploitation requires user interaction, specifically opening a malicious file. The vulnerability affects Adobe Illustrator, potentially leading to code execution upon opening malicious files. This issue requires immediate attention from Adobe Illustrator users, particularly those in creative and design teams, to assess exposure and verify their versions. The vulnerability has a high severity score and requires verification of Adobe Illustrator versions to ensure they are patched.

Defensive priority

High priority for Illustrator users to verify and update to patched versions.

Recommended defensive actions

  • Verify and apply Adobe Illustrator updates to ensure version 29.8.12 or later, or 30.9 or later.
  • Restrict user access to trusted sources for file downloads and opening.
  • Implement monitoring for suspicious file opening and execution activities.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Vendor advisory is available from Adobe. The vulnerability has been publicly disclosed and requires verification of Adobe Illustrator versions to ensure they are patched. Additional details can be found in the official CVE Program record and NIST NVD vulnerability detail pages.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75991 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75991

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75991 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75991

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.