ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-75771, an integer overflow in Adobe Photoshop's DCM JPEG-LS image parsing that enables remote code execution with user interaction.
The Zero Day Initiative published advisory ZDI-26-677 for an integer overflow in Adobe Photoshop's parsing of DCM JPEG-LS images. A remote attacker could execute arbitrary code if the target opens a malicious file or visits a malicious page. ZDI assigned a CVSS rating of 7.8. No exploitation is reported.
- CVE-2026-75771 assigned; CVSS 7.8
- User interaction required: malicious page visit or file open
- Integer overflow in DCM JPEG-LS parsing leads to RCE
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-75771 | Integer Overflow Leading to Arbitrary Code Execution in Adobe Photoshop Desktop Adobe Photoshop Desktop contains an integer overflow or wraparound condition (CWE-190) that, when the application processes a specially crafted file, can lead to arbitrary code execution. Exploitation uses a local attack vector and requires user interaction: an attacker must trick a victim into opening a malicious file, which triggers the flawed integer arithmetic. A successful attacker gains code execution in the context of the current user, meaning the privileges of the logged-in account rather than system-level control. All users running the affected desktop releases of Photoshop are potentially exposed; this data set does not include specific version ranges, which are enumerated in Adobe's security advisory. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days. Do: Update Photoshop Desktop to the fixed release listed in Adobe's security advisory (specific version numbers are not included in this data) using the Creative Cloud updater. Until patched, instruct users not to open image or design files from untrusted sources, since exploitation requires a victim to open a malicious file. Given no known PoC or in-the-wild exploitation and a low ~0.2% EPSS score, patching can follow the normal high-priority cycle rather than emergency response. | 7.8 | <1% |
| masstens of millions of desktop users (Photoshop is the flagship app of Adobe's ~30M-subscriber Creative Cloud) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.
This source does not provide full text. Read it at zerodayinitiative.com.