Description
Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap‑based buffer overflow in Photoshop Desktop allows an attacker to achieve arbitrary code execution when the victim opens a specially crafted image file. The flaw results from improper handling of memory buffers during image parsing and is classified as CWE‑122. If exploited the attacker can run code with the privileges of the current user, potentially compromising data or the entire system.

Affected Systems

The affected products include Adobe Photoshop 2025 and Adobe Photoshop 2026. Further information on patch availability should be consulted through the Adobe security advisory; the CVE does not disclose whether a patch has been released. No other Adobe products or older versions are listed as impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level, while the EPSS score is not available, so the current exploitation probability remains uncertain. The vulnerability requires user interaction—opening a malicious file—which limits passive exploitation opportunities. The flaw is not included in the CISA KEV catalog, meaning no widespread public exploit has been reported, but the nature of the flaw and the need for user interaction still present a meaningful risk for individuals or organizations that process image files.

Generated by OpenCVE AI on September 9, 2026 at 14:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Adobe security advisory at https://helpx.adobe.com/security/products/photoshop/apsb26-130.html for patch information and apply any available updates to Adobe Photoshop 2025 or 2026 that address the heap‑based buffer overflow.
  • Configure endpoint protection to detect and quarantine suspicious Photoshop image files, and consider running Photoshop in a sandboxed or restricted‑privilege environment.
  • Avoid opening image files from untrusted or unknown sources, and verify file integrity before processing.

Generated by OpenCVE AI on September 9, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe photoshop 2025
Adobe photoshop 2026

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:43.813Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-82006

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:50.747Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:48.800

Modified: 2026-09-11T19:21:33.653

Link: CVE-2026-82006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:36Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow