ZeroHour

CVE-2026-75862

mass

Integer Overflow in Adobe Photoshop Desktop Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-75862 is an integer overflow or wraparound flaw (CWE-190) in Adobe Photoshop Desktop that can be triggered when the application processes a specially crafted file, corrupting memory in a way an attacker can leverage. Exploitation requires user interaction: the victim must open a malicious file, for example an image or project document delivered via email, download, or shared storage. A successful attack yields arbitrary code execution in the context of the current user, meaning the attacker's code runs with the victim's privileges and access to their files and environment. All users of Photoshop Desktop are potentially affected, but the available data does not specify affected or fixed version numbers, so defenders should consult Adobe's official security bulletin for version details. Exploitation status is calm: there is no known public proof-of-concept, the issue is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.2%.

What to do: Update Photoshop Desktop via Creative Cloud to the latest release and check Adobe's security advisory for this CVE to identify the specific fixed build, since affected version ranges were not provided in the available data. Until patched, exercise caution with untrusted or unexpected image files opened in Photoshop, as opening a malicious file is the required attack vector. With no public PoC and no in-the-wild exploitation reported, this can be handled through normal patch cycles rather than emergency remediation.

Affected
Adobe Photoshop Desktop
Estimated exposure
masstens of millions of users (Photoshop's installed base across Creative Cloud subscribers) — Adobe does not publish exact Photoshop install counts, but Creative Cloud has reported subscriber counts in the tens of millions and Photoshop is its most widely deployed desktop application, so mass exposure is the plausible order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
photoshop
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI disclosed a CVSS 7.8 integer overflow remote code execution flaw (CVE-2026-75862) in Adobe Photoshop DCM JPEG image parsing.

The Zero Day Initiative published advisory ZDI-26-679 describing an integer overflow remote code execution vulnerability in Adobe Photoshop, tracked as CVE-2026-75862 with a CVSS 7.8 score. The flaw occurs while parsing JPEG data in DCM images. Exploitation requires user interaction: the target must visit a malicious page or open a malicious file. No in-the-wild exploitation is reported.