Description
Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in Photoshop Desktop that allows an attacker to execute arbitrary code in the context of the user who opens a malicious file. The flaw results from insufficient bounds checking on data structures used to process image files, which can compromise confidentiality, integrity, and availability for that user.

Affected Systems

Adobe Photoshop 2025 and Adobe Photoshop 2026.

Risk and Exploitability

The CVSS v3.1 score of 7.8 indicates moderate‑to‑high severity. The EPSS score is not available, but because exploitation requires user interaction—opening a crafted image file—the likelihood of exploitation is limited to environments where users can be deceived. The vulnerability is not listed in the CISA KEV catalog, so there are no publicly known exploits at this time. An attacker would need to deliver a malicious file and convince a user to open it, after which the out‑of‑bounds write could be triggered and arbitrary code executed with the user’s privileges.

Generated by OpenCVE AI on September 9, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Photoshop to the latest version that contains the fix for this vulnerability.
  • Use a sandbox or isolate Photoshop from the rest of the system to limit the impact of a malicious file if it is opened.
  • Configure anti‑malware or file‑scanning tools to detect and block suspicious image files before they can be processed by Photoshop.

Generated by OpenCVE AI on September 9, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe
Adobe photoshop 2025
Adobe photoshop 2026

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Photoshop Desktop | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:42.991Z

Reserved: 2026-08-18T01:29:54.613Z

Link: CVE-2026-75631

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:39.697Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:12.733

Modified: 2026-09-14T14:18:51.363

Link: CVE-2026-75631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:26Z

Weaknesses