ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “ZDI discloses three CVSS 7.8 integer overflow remote code execution flaws in Adobe Photoshop DCM parsing (CVE-2026-75771, CVE-2026-75862, CVE-2026-75863)” — merged summary and timeline →

ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

mediumVulnerabilityimportance 32CVE-2026-75863
AI summary · glm-5.3-flash

ZDI disclosed a CVSS 7.8 integer overflow remote code execution flaw (CVE-2026-75863) in Adobe Photoshop DCM file parsing.

The Zero Day Initiative published advisory ZDI-26-678 describing an integer overflow remote code execution vulnerability in Adobe Photoshop, tracked as CVE-2026-75863 with a CVSS 7.8 score. The flaw occurs while parsing DCM files. Exploitation requires user interaction: the target must visit a malicious page or open a malicious file. No in-the-wild exploitation is reported.

  • Integer overflow when parsing DCM files in Adobe Photoshop enables remote code execution.
  • CVSS 7.8; exploitation requires visiting a malicious page or opening a malicious file.
  • Disclosed via ZDI; no in-the-wild exploitation reported.
VendorsAdobe
ProductsPhotoshop
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-75863
Integer Overflow Leading to Arbitrary Code Execution in Adobe Photoshop Desktop

CVE-2026-75863 is an integer overflow or wraparound flaw (CWE-190) in Adobe Photoshop Desktop that can corrupt memory handling when the application processes a specially crafted file. Exploitation requires user interaction: a victim must open a malicious file, making this a local attack vector rather than a network-exposed one. If exploited, an attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability of the workstation. All users of Photoshop Desktop are potentially affected; affected version ranges are not included in the data available here and should be confirmed in Adobe's security advisory. Exploitation status is currently quiet: no public proof-of-concept, no CISA KEV listing, and an EPSS score of 0.2% (13th percentile) suggests limited near-term exploitation risk.

Do: Update Photoshop Desktop to the fixed release identified in Adobe's security bulletin and verify the installed version through the Creative Cloud desktop app. Until patched, avoid opening Photoshop documents or other supported image files from untrusted sources, especially on workstations that handle third-party files. Given the low EPSS score, absence of KEV listing, and lack of a public PoC, this can be addressed in a normal patch cycle rather than as an emergency.

7.8<1%
  • Adobe Photoshop Desktop
massmillions of desktop users (Photoshop is Adobe's flagship Creative Cloud application, whose subscriber base exceeds 20 million)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75863.

This source does not provide full text. Read it at zerodayinitiative.com.