
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82007 is an Integer Overflow or Wraparound vulnerability (CWE-190) in Adobe Photoshop Desktop that could result in arbitrary code execution in the context of the current user. Disclosed on September 8, 2026, it affects Photoshop 2025 versions up to and including 26.11.6, and Photoshop 2026 versions up to and including 27.6. Fixed versions are Photoshop 2025 26.11.7 and Photoshop 2026 27.7. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound), where a calculation in Photoshop Desktop's file parsing logic can produce an integer overflow or wraparound, causing the resulting value to wrap to a very small or negative number. This can corrupt memory in a way that enables arbitrary code execution. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted malicious file. The attack complexity is low, meaning no special conditions beyond user interaction are needed to trigger the flaw (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high impact to confidentiality, integrity, and availability. An attacker who tricks a user into opening a malicious file could gain full control of the user's session, access sensitive data, modify files, or install malware. The scope is unchanged, meaning the impact is contained to the affected Photoshop process and the current user's privileges, but this is still sufficient for significant data theft or system compromise on the victim's machine (GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.226% (14th percentile), indicating a low near-term probability of exploitation. Exploitation is not automatable, as it requires user interaction to open a malicious file, which limits mass exploitation potential.
cmd.exe, powershell.exe, bash, curl, wget) following the opening of an external file.Adobe has released patched versions addressing this vulnerability: Photoshop 2025 26.11.7 and Photoshop 2026 27.7. Users should update immediately via the Creative Cloud desktop application. As an interim measure, users should avoid opening Photoshop files received from untrusted or unknown sources. Organizations can also consider implementing application whitelisting and monitoring Photoshop processes for anomalous child process creation (Adobe Advisory, GitHub Advisory).
The vulnerability was noted by the Center for Internet Security (CIS) in an advisory covering multiple Adobe product vulnerabilities patched in September 2026, highlighting the risk of arbitrary code execution (CIS Advisory). Security aggregators including BeyondMachines and The Hacker Wire covered Adobe's September 2026 patch release. Tenable published Nessus detection plugins (343848, 343849) for the vulnerability. No significant independent researcher commentary or social media controversy has been observed beyond routine patch-cycle coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."