CVE-2026-21288: Illustrator | NULL Pointer Dereference (CWE-476)
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21288?
CVE-2026-21288 has a critical severity rating as it can lead to application denial-of-service.
How do I fix CVE-2026-21288?
To fix CVE-2026-21288, update Adobe Illustrator to version 30.1 or later.
What versions of Adobe Illustrator are impacted by CVE-2026-21288?
Adobe Illustrator versions 29.8.3, 30.0 and earlier are impacted by CVE-2026-21288.
What type of vulnerability is CVE-2026-21288?
CVE-2026-21288 is classified as a NULL Pointer Dereference vulnerability, falling under CWE-476.
What could an attacker do by exploiting CVE-2026-21288?
An attacker exploiting CVE-2026-21288 could crash the application, leading to service disruption.