
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75863 is an Integer Overflow or Wraparound vulnerability (CWE-190) in Adobe Photoshop Desktop that can result in arbitrary code execution in the context of the current user. It affects Photoshop 2025 versions up to and including 26.11.6, and Photoshop 2026 versions up to and including 27.6. The vulnerability was published on September 8, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound), occurring during file parsing within Photoshop Desktop. When processing a specially crafted file, an integer calculation produces a value that overflows or wraps around, leading to memory corruption that can be leveraged for arbitrary code execution. Exploitation requires no special privileges but does require user interaction — specifically, a victim must open a malicious file (e.g., a crafted image or Photoshop document). The attack vector is local, meaning the malicious file must be delivered to and opened on the victim's machine (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high impact to confidentiality, integrity, and availability. An attacker who tricks a user into opening a malicious file could gain full control of the user's session, access sensitive data, modify files, or install malware. The scope is unchanged, meaning the impact is contained to the user's context, but this is still sufficient for significant data theft or system compromise on the affected workstation (GitHub Advisory).
As of the disclosure date, there are no known public proof-of-concept exploits and no confirmed in-the-wild exploitation of CVE-2026-75863 (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the requirement for user interaction. The EPSS score is approximately 0.226% (13th percentile), indicating a low near-term probability of exploitation. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.
%APPDATA%, ~/Library/) shortly after opening a Photoshop file; new or modified scripts, executables, or scheduled tasks created by the Photoshop process.cmd.exe, powershell.exe, bash, curl, wget); Photoshop process crashing or exhibiting abnormal memory usage upon opening a specific file.Adobe has released patched versions addressing this vulnerability: Photoshop 2025 version 26.11.7 and Photoshop 2026 version 27.7. Users should update to these versions or later immediately via the Creative Cloud desktop application or Adobe's update mechanism (Adobe Advisory). As a general precaution prior to patching, users should avoid opening Photoshop files from untrusted or unknown sources. Organizations should also consider applying application allowlisting and monitoring for unusual child processes spawned by Photoshop.
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). Tenable published Nessus detection plugins (IDs 343848 and 343849) for this vulnerability shortly after disclosure. Coverage was also noted by security aggregators such as BeyondMachines and Meterpreter.org in the context of Adobe's September 2026 patch release cycle.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."