ZeroHour

CVE-2026-75863

mass

Integer Overflow Leading to Arbitrary Code Execution in Adobe Photoshop Desktop

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-75863 is an integer overflow or wraparound flaw (CWE-190) in Adobe Photoshop Desktop that can corrupt memory handling when the application processes a specially crafted file. Exploitation requires user interaction: a victim must open a malicious file, making this a local attack vector rather than a network-exposed one. If exploited, an attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability of the workstation. All users of Photoshop Desktop are potentially affected; affected version ranges are not included in the data available here and should be confirmed in Adobe's security advisory. Exploitation status is currently quiet: no public proof-of-concept, no CISA KEV listing, and an EPSS score of 0.2% (13th percentile) suggests limited near-term exploitation risk.

What to do: Update Photoshop Desktop to the fixed release identified in Adobe's security bulletin and verify the installed version through the Creative Cloud desktop app. Until patched, avoid opening Photoshop documents or other supported image files from untrusted sources, especially on workstations that handle third-party files. Given the low EPSS score, absence of KEV listing, and lack of a public PoC, this can be addressed in a normal patch cycle rather than as an emergency.

Affected
Adobe Photoshop Desktop
Estimated exposure
massmillions of desktop users (Photoshop is Adobe's flagship Creative Cloud application, whose subscriber base exceeds 20 million) — Adobe has publicly reported a Creative Cloud subscriber base above 20 million and Photoshop is its most widely deployed desktop application, making an installed base in the millions a reasonable order-of-magnitude estimate; actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
photoshop
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI disclosed a CVSS 7.8 integer overflow remote code execution flaw (CVE-2026-75863) in Adobe Photoshop DCM file parsing.

The Zero Day Initiative published advisory ZDI-26-678 describing an integer overflow remote code execution vulnerability in Adobe Photoshop, tracked as CVE-2026-75863 with a CVSS 7.8 score. The flaw occurs while parsing DCM files. Exploitation requires user interaction: the target must visit a malicious page or open a malicious file. No in-the-wild exploitation is reported.