ZeroHour

CVE-2026-75771

mass

Integer Overflow Leading to Arbitrary Code Execution in Adobe Photoshop Desktop

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

Adobe Photoshop Desktop contains an integer overflow or wraparound condition (CWE-190) that, when the application processes a specially crafted file, can lead to arbitrary code execution. Exploitation uses a local attack vector and requires user interaction: an attacker must trick a victim into opening a malicious file, which triggers the flawed integer arithmetic. A successful attacker gains code execution in the context of the current user, meaning the privileges of the logged-in account rather than system-level control. All users running the affected desktop releases of Photoshop are potentially exposed; this data set does not include specific version ranges, which are enumerated in Adobe's security advisory. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.

What to do: Update Photoshop Desktop to the fixed release listed in Adobe's security advisory (specific version numbers are not included in this data) using the Creative Cloud updater. Until patched, instruct users not to open image or design files from untrusted sources, since exploitation requires a victim to open a malicious file. Given no known PoC or in-the-wild exploitation and a low ~0.2% EPSS score, patching can follow the normal high-priority cycle rather than emergency response.

Affected
Adobe Photoshop (Desktop)
Estimated exposure
masstens of millions of desktop users (Photoshop is the flagship app of Adobe's ~30M-subscriber Creative Cloud) — Adobe does not publish per-application install counts, but Photoshop is the most widely deployed application in a Creative Cloud ecosystem reported to exceed 30 million subscribers, so the installed desktop base is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
photoshop
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-75771, an integer overflow in Adobe Photoshop's DCM JPEG-LS image parsing that enables remote code execution with user interaction.

The Zero Day Initiative published advisory ZDI-26-677 for an integer overflow in Adobe Photoshop's parsing of DCM JPEG-LS images. A remote attacker could execute arbitrary code if the target opens a malicious file or visits a malicious page. ZDI assigned a CVSS rating of 7.8. No exploitation is reported.