THREAT OPS › Threat News › [NVD] CVE-2026-21280 (HIGH 8.6) — Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker
[NVD] CVE-2026-21280 (HIGH 8.6) — Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker
CVE-2026-21280 CVSS: 8.6 HIGH Published: 2026-01-13T19:16:25.693
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious
MITRE ATT&CK techniques
- Malicious FileT1204.002
Indicators of compromise
- CVE-2026-21280cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21280