ZeroHour

CVE-2026-82007

mass

Integer Overflow in Adobe Photoshop Desktop Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-82007 is an integer overflow or wraparound vulnerability (CWE-190) in Adobe Photoshop Desktop that can be reached when the application processes a maliciously crafted file. Exploitation requires user interaction, as a victim must open the attacker-supplied file, after which the integer handling error can lead to arbitrary code execution. A successful attacker gains the ability to run code with the privileges of the current user, typically enabling data theft, malware installation, or further compromise of the user's workstation. All users of the affected Photoshop Desktop release are exposed, but the supplied data does not specify exact affected version ranges or fixed builds, so defenders must consult Adobe's security advisory for those details. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.2% (13th percentile) probability of exploitation within 30 days.

What to do: Check installed Photoshop Desktop builds against Adobe's advisory for CVE-2026-82007 and update to the fixed release via Creative Cloud as soon as it is published, since the supplied data does not name affected or fixed versions. Until systems are patched, instruct users not to open Photoshop-compatible files from untrusted or unexpected sources, because opening a crafted file is the only known trigger. With no public PoC, no in-the-wild exploitation, and 0.2% EPSS, this can be handled in a normal patch cycle rather than as an emergency.

Affected
Adobe Photoshop Desktop
Estimated exposure
masstens of millions of Photoshop Desktop users (est.) — Photoshop is Adobe's flagship desktop application with a widely reported user base in the tens of millions, so every user of an affected desktop build who opens an untrusted file is plausibly exposed, far above the 1M-user mass threshold.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
photoshop
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.