AI analysis
CVE-2026-75862 is an integer overflow or wraparound flaw (CWE-190) in Adobe Photoshop Desktop that can be triggered when the application processes a specially crafted file, corrupting memory in a way an attacker can leverage. Exploitation requires user interaction: the victim must open a malicious file, for example an image or project document delivered via email, download, or shared storage. A successful attack yields arbitrary code execution in the context of the current user, meaning the attacker's code runs with the victim's privileges and access to their files and environment. All users of Photoshop Desktop are potentially affected, but the available data does not specify affected or fixed version numbers, so defenders should consult Adobe's official security bulletin for version details. Exploitation status is calm: there is no known public proof-of-concept, the issue is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.2%.
What to do: Update Photoshop Desktop via Creative Cloud to the latest release and check Adobe's security advisory for this CVE to identify the specific fixed build, since affected version ranges were not provided in the available data. Until patched, exercise caution with untrusted or unexpected image files opened in Photoshop, as opening a malicious file is the required attack vector. With no public PoC and no in-the-wild exploitation reported, this can be handled through normal patch cycles rather than emergency remediation.
Estimated exposure
masstens of millions of users (Photoshop's installed base across Creative Cloud subscribers) — Adobe does not publish exact Photoshop install counts, but Creative Cloud has reported subscriber counts in the tens of millions and Photoshop is its most widely deployed desktop application, so mass exposure is the plausible order of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.