CVE-2026-21288Medium· 5.5▾ SunlitIllustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disru…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
illustrator >= 29.0, < 29.8.4illustrator = 30.0Upgrade past the affected range:
illustrator 29.8.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-21280High· 8.6Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-76192Medium· 5.5InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service
CVE-2026-84396Medium· 5.5InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service
CVE-2026-75991High· 8.6Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-75992High· 7.8Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-75990High· 8.6Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user