CVE-2026-27270

Summary

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Software

VendorProductVersion RangeStatus
AdobeIllustrator Desktop 20260 <= 30.1affected
AdobeIllustrator Desktop 202630.2unaffected
AdobeIllustrator Desktop 20250 <= 29.8.4affected
AdobeIllustrator Desktop 202529.8.5unaffected

Weaknesses

  • CWE-125: Out-of-bounds Read (CWE-125)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References