CVE-2026-48275
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the curren
CVSS
8.6
High
EPSS
0.2%
p6
KEV
—
Exploit Today
2
0-100
Published: Jul 14, 2026 · Last modified: Jul 16, 2026 · CWE-426
0.2%EPSS · 30 days0.2%
2026-07-152026-07-28
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-483958.6 HIG—
——0Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.7hCVE-2026-483918.2 HIG—
——0Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.7hCVE-2026-630938.8 HIG37.0%
——11Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.12dCVE-2026-482877.4 HIG3.7%
——1CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.13dCVE-2026-483467.9 HIG8.6%
——3Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.13dCVE-2026-570976.4 MED24.6%
——7Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.7d