Description
Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Patch
AI Analysis

Impact

Photoshop Desktop contains an out‑of‑bounds write flaw (CWE‑787) that allows an attacker to write arbitrary data outside the bounds of a buffer when parsing a maliciously crafted document. If the victim opens the file, the memory corruption can lead to the execution of arbitrary code in the context of the user running Photoshop. The vulnerability does not provide a remote trigger and requires user interaction to be exploited.

Affected Systems

Adobe Photoshop 2025 and Adobe Photoshop 2026 are affected. No specific patch versions are listed beyond the product line, but the Adobe Security Bulletin APSB26‑130 addresses this flaw.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% signals a very low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog, and it requires that a user manually open a malicious file. Consequently, the risk is primarily confined to users who may inadvertently open compromised Photoshop documents.

Generated by OpenCVE AI on September 9, 2026 at 14:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe Photoshop update issued in APSB26‑130 to fix the out‑of‑bounds write vulnerability.
  • Restrict Photoshop from opening files from untrusted or unknown sources, or enable file‑type filtering to block suspicious documents.
  • Run Photoshop in a sandboxed environment or virtual machine to contain potential exploitation in the event a malicious file is opened.

Generated by OpenCVE AI on September 9, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe photoshop 2025
Adobe photoshop 2026

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Photoshop Desktop | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:43.481Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-82005

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:46.405Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:48.667

Modified: 2026-09-11T18:40:12.877

Link: CVE-2026-82005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:31Z

Weaknesses