Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76199
Adobe Photoshop vulnerability analysis and mitigation

Overview

CVE-2026-76199 is an Uncontrolled Search Path Element vulnerability (CWE-427) in Adobe Photoshop Desktop that allows arbitrary code execution in the context of the current user. It affects Photoshop 2025 versions up to and including 26.11.6, and Photoshop 2026 versions up to and including 27.6. The vulnerability was published on September 8, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).

Technical details

The vulnerability is classified as CWE-427 (Uncontrolled Search Path Element), meaning Photoshop Desktop uses a search path that includes one or more locations controllable by an attacker. Exploitation occurs locally when a victim opens a specially crafted malicious file, triggering Photoshop to load a resource (such as a DLL or dynamic library) from an attacker-controlled path instead of the intended trusted location — a technique consistent with DLL Search Order Hijacking (MITRE ATT&CK T1574.001) or Dylib Hijacking (T1574.004). The attack requires no privileges from the attacker but does require user interaction (opening the malicious file), and the scope is marked as changed, indicating impact can extend beyond the Photoshop process itself (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation results in arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive data accessible to the user, modify or delete files, and disrupt system availability. Because the scope is changed, the impact may extend beyond the Photoshop application boundary to affect other system components or resources (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable, as it requires a victim to manually open a malicious file. The EPSS score is approximately 0.211% (12th percentile), indicating a low near-term probability of exploitation. CVE-2026-76199 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Craft a malicious file: Prepare a specially crafted file (e.g., a PSD or supported image format) that, when opened by Photoshop, triggers a search path lookup for a DLL or library resource.
  2. Plant a malicious library: Place a malicious DLL or dynamic library in a directory that Photoshop's uncontrolled search path will traverse before reaching the legitimate library location (e.g., the same directory as the malicious file, or a writable directory earlier in the search path).
  3. Deliver the malicious file: Use social engineering, phishing, or a compromised file-sharing channel to deliver the crafted file to a victim running a vulnerable version of Photoshop (2025 ≤ 26.11.6 or 2026 ≤ 27.6).
  4. Victim opens the file: When the victim opens the malicious file in Photoshop Desktop, the application loads the attacker-controlled library from the manipulated search path.
  5. Achieve code execution: The malicious library executes arbitrary code in the context of the current user, potentially enabling data exfiltration, persistence mechanisms, or further lateral movement (GitHub Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Photoshop process (e.g., cmd.exe, powershell.exe, bash, curl, or network utilities) shortly after a file is opened.
  • File System: Presence of unexpected DLL or dynamic library files in directories co-located with Photoshop project files or in user-writable directories on the search path; newly created or modified executables in user-accessible locations.
  • Logs: Windows Event Logs or macOS unified logs showing Photoshop loading libraries from non-standard or user-writable paths; application crash logs or error entries related to unexpected module loads.
  • Network: Unusual outbound network connections originating from the Photoshop process or its child processes to unknown external IP addresses or domains.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Photoshop 2025 version 26.11.7 and Photoshop 2026 version 27.7. Users should update immediately via the Creative Cloud desktop application. As interim mitigations, users should avoid opening Photoshop files from untrusted or unknown sources, and administrators should consider restricting write access to directories in Photoshop's library search path. Monitoring for suspicious Photoshop execution patterns is also recommended (Adobe Advisory, GitHub Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). AusCERT published a bulletin (ESB-2026.10694) covering the Adobe September 2026 patch release. Tenable released Nessus detection plugins (IDs 343848 and 343849) for this vulnerability. Community discussion has been limited, consistent with the low EPSS score and absence of public exploits.

Additional resources


SourceThis report was generated using AI

Related Adobe Photoshop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76199HIGH8.6
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-82007HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-82006HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-82005HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-75863HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management