CVE-2026-71441: Illustrator | Out-of-bounds Read (CWE-125)
Published Aug 25, 2026
·Updated
Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
5 affected components
Adobe Illustrator
All of the following
Any of the following
Adobe Illustrator>=29.0<29.8.10
Adobe Illustrator>=30.0<30.7
Any of the following
Apple macOS
Microsoft Windows
Event History
Aug 25, 2026
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who is exposed to exploitation?
Users of Adobe Illustrator who open a malicious file are exposed. The vulnerability has local attack vector, and exploitation requires user interaction.
2
What could an attacker obtain through successful exploitation?
Successful exploitation could disclose sensitive information from memory. The provided information does not indicate impacts to integrity or availability.
3
What should be prioritized while patching is pending?
Avoid opening untrusted or unsolicited files in Illustrator, since opening a malicious file is required for exploitation.