CVE-2026-82006
massHeap Buffer Overflow in Adobe Photoshop Desktop Allows Code Execution via Files
CVE-2026-82006 is a heap-based buffer overflow (CWE-122) in Adobe Photoshop Desktop that could lead to arbitrary code execution in the context of the current user. Triggering the flaw requires user interaction: a victim must open a malicious file, so attackers would need to deliver a crafted file (e.g., via email, download, or shared storage) to a target. If exploited, the attacker gains code execution with the privileges of the logged-in user, with high impact on confidentiality, integrity, and availability. Users of Photoshop Desktop are potentially affected; the source data does not specify affected or fixed version ranges, so defenders should consult Adobe's security advisory for exact versions. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low (0.2%, 16th percentile), indicating no confirmed exploitation at this time.
What to do: Update Photoshop Desktop to the patched version listed in Adobe's security advisory once applied, and verify installed builds against the advisory's fixed-version list since the data here does not include version ranges. Until patching, exercise caution with image and document files from untrusted sources, as opening a malicious file is the required trigger. Because exploitation has not been observed and no PoC is public, prioritize patching by user exposure (e.g., users who routinely open third-party files) rather than as an emergency.
| Adobe Photoshop Desktop | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- photoshop
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.