Description
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

The issue is an integer overflow or wraparound in Photoshop Desktop that can be triggered by opening a specially crafted file. When exploited, the overflow enables the attacker to execute arbitrary code in the context of the currently logged‑in user, potentially compromising the entire workstation.

Affected Systems

Adobe Photoshop 2025 and Adobe Photoshop 2026 are affected.

Risk and Exploitability

The vulnerability is scored 7.8 on the CVSS scale, indicating a high level of risk. The EPSS score is not available, and it is not listed in CISA's KEV catalog, so no publicly known active exploits have been reported. The exploit requires user interaction – a victim must open a malicious file – but once that occurs, the attacker can run code with the victim’s privileges. The combination of a high CVSS score and the requirement for a user action places this flaw in the medium‑high risk band for organizations that handle untrusted PDF or image files.

Generated by OpenCVE AI on September 9, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Photoshop update that addresses the integer overflow flaw
  • Keep antivirus and anti‑malware solutions fully updated to detect malicious files
  • Limit the opening of unknown or untrusted files by using file‑type whitelisting or user‑education campaigns

Generated by OpenCVE AI on September 9, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe photoshop 2025
Adobe photoshop 2026

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:43.965Z

Reserved: 2026-08-18T11:07:05.686Z

Link: CVE-2026-75863

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:52.914Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:22.470

Modified: 2026-09-11T18:32:31.353

Link: CVE-2026-75863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:38Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound