ZeroHour
Story · 1 source · 3 articlesfirst updated ()

ZDI discloses three CVSS 7.8 integer overflow remote code execution flaws in Adobe Photoshop DCM parsing (CVE-2026-75771, CVE-2026-75862, CVE-2026-75863)

What's new: First merged summary for this story (no prior summary existed): three new ZDI advisories (ZDI-26-677, ZDI-26-678, ZDI-26-679) disclosed three distinct Adobe Photoshop DCM integer overflow remote code execution vulnerabilities (CVE-2026-75771, CVE-2026-75862, CVE-2026-75863) on 2026-09-10.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-10, the Zero Day Initiative published three advisories (ZDI-26-677, ZDI-26-678, ZDI-26-679), each describing a distinct CVSS 7.8 integer overflow that allows remote code execution when Adobe Photoshop parses DCM files, JPEG data in DCM images, or…

The Zero Day Initiative published three separate advisories on 2026-09-10 (2026-09-10T05:00:00.000Z) covering integer overflow remote code execution vulnerabilities in Adobe Photoshop's parsing of DCM content. Each advisory targets a different parsing path: ZDI-26-678 (CVE-2026-75863) covers an integer overflow while parsing DCM files; ZDI-26-679 (CVE-2026-75862) covers an integer overflow while parsing JPEG data in DCM images; and ZDI-26-677 (CVE-2026-75771) covers an integer overflow while parsing JPEG-LS images in DCM. All three vulnerabilities are rated CVSS 7.8 and could allow a remote attacker to execute arbitrary code. Exploitation of all three requires user interaction: the target must visit a malicious page or open a malicious file. ZDI reports no in-the-wild exploitation for any of the three flaws. The three reports are mutually consistent; there are no discrepancies between them.

  • ZDI-26-678 (CVE-2026-75863): integer overflow when parsing DCM files in Adobe Photoshop enables remote code execution; CVSS 7.8.
  • ZDI-26-679 (CVE-2026-75862): integer overflow when parsing JPEG data in DCM images in Adobe Photoshop enables remote code execution; CVSS 7.8.
  • ZDI-26-677 (CVE-2026-75771): integer overflow when parsing JPEG-LS images in DCM in Adobe Photoshop enables remote code execution; CVSS 7.8.
  • All three advisories were published on 2026-09-10 (2026-09-10T05:00:00.000Z).
  • Exploitation of all three vulnerabilities requires user interaction: the target must visit a malicious page or open a malicious file.
  • No in-the-wild exploitation is reported for any of the three vulnerabilities.
  • The three source reports agree on all figures, CVE assignments, and dates; no source conflicts.

Coverage timeline

  1. · 5d ago
    ZDI Published Advisories· 32
    ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

    ZDI disclosed a CVSS 7.8 integer overflow remote code execution flaw (CVE-2026-75863) in Adobe Photoshop DCM file parsing.

  2. · 5d ago
    ZDI Published Advisories· 24
    ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-75771, an integer overflow in Adobe Photoshop's DCM JPEG-LS image parsing that enables remote code execution with user interaction.

  3. · 5d ago
    ZDI Published Advisories· 32
    ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability

    ZDI disclosed a CVSS 7.8 integer overflow remote code execution flaw (CVE-2026-75862) in Adobe Photoshop DCM JPEG image parsing.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-75771
+2 in the same advisory: …75862 …75863
Integer Overflow Leading to Arbitrary Code Execution in Adobe Photoshop Desktop

Adobe Photoshop Desktop contains an integer overflow or wraparound condition (CWE-190) that, when the application processes a specially crafted file, can lead to arbitrary code execution. Exploitation uses a local attack vector and requires user interaction: an attacker must trick a victim into opening a malicious file, which triggers the flawed integer arithmetic. A successful attacker gains code execution in the context of the current user, meaning the privileges of the logged-in account rather than system-level control. All users running the affected desktop releases of Photoshop are potentially exposed; this data set does not include specific version ranges, which are enumerated in Adobe's security advisory. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.

Do: Update Photoshop Desktop to the fixed release listed in Adobe's security advisory (specific version numbers are not included in this data) using the Creative Cloud updater. Until patched, instruct users not to open image or design files from untrusted sources, since exploitation requires a victim to open a malicious file. Given no known PoC or in-the-wild exploitation and a low ~0.2% EPSS score, patching can follow the normal high-priority cycle rather than emergency response.

7.8<1%
  • Adobe Photoshop (Desktop)
masstens of millions of desktop users (Photoshop is the flagship app of Adobe's ~30M-subscriber Creative Cloud)