CVE-2026-21333: Illustrator | Untrusted Search Path (CWE-426)
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21333?
CVE-2026-21333 has a severity rating that indicates a significant risk due to the potential for arbitrary code execution.
How do I fix CVE-2026-21333?
To fix CVE-2026-21333, update Adobe Illustrator to version 30.2 or later as per the latest security guidance.
What versions of Illustrator are affected by CVE-2026-21333?
CVE-2026-21333 affects Adobe Illustrator versions 29.8.4, 30.1 and earlier.
What type of vulnerability is CVE-2026-21333?
CVE-2026-21333 is classified as an Untrusted Search Path vulnerability.
What do attackers achieve by exploiting CVE-2026-21333?
Exploitation of CVE-2026-21333 may allow attackers to execute arbitrary code in the context of the current user.