Adobe Illustrator 存在一个认证错误(Incorrect Authorization)漏洞,可能导致在当前用户上下文中执行任意代码。攻击者可利用此漏洞执行任意代码。利用该漏洞需要用户交互,即受害者必须打开一个恶意文件。漏洞的影响范围(Scope)发生了变化。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Adobe | Illustrator Desktop 2025 | ≤ 29.8.10 |
affected |
29.8.11 |
unaffected | ||
| Adobe | Illustrator Desktop 2026 | ≤ 30.7 |
affected |
30.8 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Illustrator Desktop 2026 | 0 ~ 30.7 | - |
|
| Adobe | Illustrator Desktop 2025 | 0 ~ 29.8.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82004 | 10.0 CRITICAL | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS C |
| CVE-2026-48273 | 9.9 CRITICAL | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval In |
| CVE-2026-19232 | 9.9 CRITICAL | Adobe Experience Manager | Incorrect Authorization (CWE-863) |
| CVE-2026-76201 | 9.3 CRITICAL | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-76200 | 9.3 CRITICAL | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75746 | 9.1 CRITICAL | ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje |
| CVE-2026-81996 | 8.8 HIGH | Acrobat Reader | Incorrect Authorization (CWE-863) |
| CVE-2026-77111 | 8.7 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77774 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77109 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-76190 | 8.6 HIGH | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval In |
| CVE-2026-75991 | 8.6 HIGH | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-76199 | 8.6 HIGH | Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-75993 | 8.5 HIGH | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-75999 | 8.4 HIGH | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-81994 | 8.2 HIGH | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Proto |
| CVE-2026-76202 | 8.2 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-76191 | 8.2 HIGH | Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-81983 | 7.8 HIGH | Acrobat Reader | Out-of-bounds Write (CWE-787) |
| CVE-2026-79908 | 7.8 HIGH | Acrobat Reader | Out-of-bounds Write (CWE-787) |
Showing top 20 of 167 CVEs. View all on vendor page → →
No comments yet