Description
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

An Integer Overflow or Wraparound flaw exists in Photoshop Desktop that allows an attacker to execute arbitrary code in the context of the current user. The vulnerability is a classic integer overflow (CWE-190) which can be triggered when a malicious file is processed by Photoshop. If exploited, the attacker gains the rights of the logged‑in user and can run code of their choosing, leading to full system compromise.

Affected Systems

Adobe offers the flaw in two recent releases: Photoshop 2025 and Photoshop 2026. Both editions are affected by the integer overflow vulnerability and must be updated to a patched release.

Risk and Exploitability

The CVSS score of 7.8 indicates high impact with a moderate to high exploitation difficulty. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious Photoshop file. If successful, the attacker could execute code in the context of the logged‑in user. No explicit network‑based exploitation is mentioned in the CVE data, and the description does not indicate privilege escalation beyond the current user's rights.

Generated by OpenCVE AI on September 9, 2026 at 14:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Photoshop update that removes the integer overflow vulnerability.
  • If an update is not yet available, avoid opening any Photoshop files from untrusted or unknown sources until the patch is installed.
  • If you cannot update immediately, run Photoshop inside a sandbox or virtual machine to isolate the environment and prevent the malicious code from affecting the host system.

Generated by OpenCVE AI on September 9, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe photoshop 2025
Adobe photoshop 2026

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:43.641Z

Reserved: 2026-08-27T21:20:45.368Z

Link: CVE-2026-82007

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:48.500Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:49.377

Modified: 2026-09-11T19:20:04.363

Link: CVE-2026-82007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:33Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound