CVE-2026-82007
massInteger Overflow in Adobe Photoshop Desktop Allows Arbitrary Code Execution
CVE-2026-82007 is an integer overflow or wraparound vulnerability (CWE-190) in Adobe Photoshop Desktop that can be reached when the application processes a maliciously crafted file. Exploitation requires user interaction, as a victim must open the attacker-supplied file, after which the integer handling error can lead to arbitrary code execution. A successful attacker gains the ability to run code with the privileges of the current user, typically enabling data theft, malware installation, or further compromise of the user's workstation. All users of the affected Photoshop Desktop release are exposed, but the supplied data does not specify exact affected version ranges or fixed builds, so defenders must consult Adobe's security advisory for those details. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.2% (13th percentile) probability of exploitation within 30 days.
What to do: Check installed Photoshop Desktop builds against Adobe's advisory for CVE-2026-82007 and update to the fixed release via Creative Cloud as soon as it is published, since the supplied data does not name affected or fixed versions. Until systems are patched, instruct users not to open Photoshop-compatible files from untrusted or unexpected sources, because opening a crafted file is the only known trigger. With no public PoC, no in-the-wild exploitation, and 0.2% EPSS, this can be handled in a normal patch cycle rather than as an emergency.
| Adobe Photoshop Desktop | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- photoshop
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.