Description
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Apply patch
AI Analysis

Impact

Photoshop Desktop suffers from an integer overflow or wraparound flaw that can enable an attacker to execute arbitrary code in the user’s context. The vulnerability arises when processing a crafted file and can lead to a compromise of confidentiality, integrity, or availability of the affected system. The issue is classified as CWE‑190, reflecting a typical overflow weakness.

Affected Systems

Adobe Photoshop 2025 and Adobe Photoshop 2026 desktop editions are affected.

Risk and Exploitability

The CVSS score of 7.8 places the vulnerability in the high risk range, indicating significant potential impact. The EPSS score is not available, so the likelihood of widespread exploitation is uncertain, but the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction; a victim must open a malicious file crafted by an attacker. Based on the description, it is inferred that the attack vector is likely a phishing or social‑engineering scenario where the user is lured into opening a malicious image or document file.

Generated by OpenCVE AI on September 9, 2026 at 14:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Adobe Photoshop security patch available from Adobe’s support portal.
  • Configure Photoshop and operating system to enforce automatic updates and apply them promptly.
  • Limit file opening to trusted sources and consider using application sandboxing or antivirus scanning on malicious files.

Generated by OpenCVE AI on September 9, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe photoshop 2025
Adobe photoshop 2026

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:43.146Z

Reserved: 2026-08-18T11:07:05.686Z

Link: CVE-2026-75862

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:41.842Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:22.353

Modified: 2026-09-11T18:32:27.863

Link: CVE-2026-75862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:27Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound