ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability
ZDI disclosed a CVSS 7.8 integer overflow remote code execution flaw (CVE-2026-75862) in Adobe Photoshop DCM JPEG image parsing.
The Zero Day Initiative published advisory ZDI-26-679 describing an integer overflow remote code execution vulnerability in Adobe Photoshop, tracked as CVE-2026-75862 with a CVSS 7.8 score. The flaw occurs while parsing JPEG data in DCM images. Exploitation requires user interaction: the target must visit a malicious page or open a malicious file. No in-the-wild exploitation is reported.
- Integer overflow when parsing DCM JPEG images in Adobe Photoshop enables remote code execution.
- CVSS 7.8; exploitation requires visiting a malicious page or opening a malicious file.
- Disclosed via ZDI; no in-the-wild exploitation reported.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-75862 | Integer Overflow in Adobe Photoshop Desktop Allows Arbitrary Code Execution CVE-2026-75862 is an integer overflow or wraparound flaw (CWE-190) in Adobe Photoshop Desktop that can be triggered when the application processes a specially crafted file, corrupting memory in a way an attacker can leverage. Exploitation requires user interaction: the victim must open a malicious file, for example an image or project document delivered via email, download, or shared storage. A successful attack yields arbitrary code execution in the context of the current user, meaning the attacker's code runs with the victim's privileges and access to their files and environment. All users of Photoshop Desktop are potentially affected, but the available data does not specify affected or fixed version numbers, so defenders should consult Adobe's official security bulletin for version details. Exploitation status is calm: there is no known public proof-of-concept, the issue is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.2%. Do: Update Photoshop Desktop via Creative Cloud to the latest release and check Adobe's security advisory for this CVE to identify the specific fixed build, since affected version ranges were not provided in the available data. Until patched, exercise caution with untrusted or unexpected image files opened in Photoshop, as opening a malicious file is the required attack vector. With no public PoC and no in-the-wild exploitation reported, this can be handled through normal patch cycles rather than emergency remediation. | 7.8 | <1% |
| masstens of millions of users (Photoshop's installed base across Creative Cloud subscribers) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.
This source does not provide full text. Read it at zerodayinitiative.com.