Illustrator
Vendor:
First CVE: Feb 2, 2006 · Active for 20 years
178
Total CVEs
More Total CVEs than 99% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Illustrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2006
20 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Illustrator178 CVEs
33%
66%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local157 (88.2%)
Network6 (3.4%)
Unknown14 (7.9%)
Physical0 (0.0%)
Adjacent Network1 (0.6%)
Attack Complexity
Low163 (91.6%)
High1 (0.6%)
Unknown14 (7.9%)
User Interaction
None0 (0.0%)
Unknown14 (7.9%)
Required164 (92.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None164 (92.1%)
Unknown14 (7.9%)
Top CVEs
Signals from CVEs in this product scope (178 CVEs).
178 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4195HIGH Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated | Dec 4, 2009 | 9.3 | 80 | NO | YES |
CVE-2007-2365HIGH Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted | Apr 30, 2007 | 9.3 | 66 | NO | YES |
CVE-2007-2244HIGH Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DI | Apr 25, 2007 | 9.3 | 58 | NO | YES |
CVE-2012-0780HIGH Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE | May 9, 2012 | 10.0 | 47 | NO | YES |
CVE-2010-3152HIGH Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execu | Aug 27, 2010 | 9.3 | 46 | NO | YES |
CVE-2026-48334CRITICAL Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated | Jul 14, 2026 | 9.6 | 42 | NO | NO |
CVE-2012-2024HIGH Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE | May 9, 2012 | 10.0 | 37 | NO | NO |
CVE-2026-48275HIGH Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi | Jul 14, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-48336HIGH Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require | Jul 14, 2026 | 7.8 | 35 | NO | NO |
CVE-2026-48337HIGH Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require | Jul 14, 2026 | 7.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (178 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
2.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (178 CVEs).
Media Mentions
Signals from CVEs in this product scope (178 CVEs).
Top CNAs Publishing CVEs For Illustrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| cs3 | 3 | 7.7 | 29.3% | 0 | 2 |
| cs2 | 1 | 9.3 | 5.2% | 0 | 0 |
| cs | 1 | 4.6 | 1.3% | 0 | 0 |
| 9.0 | 7 | 9.2 | 6.0% | 0 | 1 |
| 8.0 | 7 | 9.2 | 6.0% | 0 | 1 |
| 7.0 | 7 | 9.2 | 6.0% | 0 | 1 |
| 30.0 | 2 | 7.0 | 0.2% | 0 | 0 |
| 29.0 | 2 | 6.7 | 0.3% | 0 | 0 |
| 28.0 | 3 | 7.8 | 0.4% | 0 | 0 |
| 27.0 | 4 | 5.5 | 0.5% | 0 | 0 |
| 26.0.1 | 2 | 5.5 | 1.4% | 0 | 0 |
| 26.0 | 2 | 5.5 | 1.4% | 0 | 0 |
| 16.2.1 | 1 | 10.0 | 5.6% | 0 | 0 |
| 16.2.0 | 1 | 10.0 | 5.6% | 0 | 0 |
| 16.0.3 | 1 | 10.0 | 5.6% | 0 | 0 |
| 16.0.2 | 1 | 10.0 | 5.6% | 0 | 0 |
| 16.0.1 | 1 | 10.0 | 5.6% | 0 | 0 |
| 15.0.1 | 1 | 9.3 | 16.9% | 0 | 1 |
| 15.0 | 6 | 10.0 | 6.7% | 0 | 1 |
| 14.0.0 | 2 | 9.7 | 39.3% | 0 | 1 |