CVE-2026-21333Disclosure(adobe / illustrator)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe illustrator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • illustrator
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-11); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
illustratorwindows

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-10: 1Mentions · 2026-03-11: 3Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 303-1003-1103-18
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-113
Disclosure3
2026-03-181
General1
Full discourse5 posts
  • dbugs@ptdbugs
    Disclosure

    Illustrator | Untrusted Search Path (CWE-426) CVE: CVE-2026-21333 PT-Identifier: PT-2026-24499 Vendor: Adobe Product: Illustrator CVSS: 8.6 Credits: n/a Description: Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21333 • https://helpx.adobe.com/security/products/illustrator/apsb26-18.html #dbugs_vuln

    Post summary

    CVE‑2026‑21333 is an untrusted search path vulnerability in Adobe Illustrator that could lead to arbitrary code execution with user interaction; Adobe has released a patch, as referenced by its advisory.

    0000150
    556 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21333 Untrusted Search Path Vulnerability in Adobe Illustrator Versions 29.8.4 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21333

    Post summary

    The text announces an untrusted search path vulnerability (CVE-2026-21333) affecting Adobe Illustrator 29.8.4 and earlier, without mentioning any PoC, exploit, patch, or active exploitation.

    0001036
    4.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-27269 ❗ CVE-2026-27220 ❗ CVE-2026-21333 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-adobe-5/ https://t.co/mhbCIV7C5l

    Post summary

    The post announces three new Adobe product CVEs and links to a source for additional information, but provides no technical or operational details.

    0000094
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21333 Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the conte… https://www.cve.org/CVERecord?id=CVE-2026-21333

    Post summary

    The text announces CVE-2026-21333, an Untrusted Search Path vulnerability in certain Illustrator versions that could lead to arbitrary code execution, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000186
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21333: HIGH] Critical vulnerability in Adobe Illustrator versions 29.8.4, 30.1 allows arbitrary code execution via an Untrusted Search Path flaw. Users must be cautious while opening files.#cve,CVE-2026-21333,#cybersecurity https://cvefind.com/CVE-2026-21333

    Post summary

    The post announces CVE-2026-21333 as a high‑severity arbitrary code execution vulnerability in Adobe Illustrator via an Untrusted Search Path flaw, but it does not provide PoC, exploitation tools, or patch information.

    0000047
    601 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeillustrator---
OSmicrosoftwindows---

Explore more