Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-82007
Adobe Photoshop vulnerability analysis and mitigation

Overview

CVE-2026-82007 is an Integer Overflow or Wraparound vulnerability (CWE-190) in Adobe Photoshop Desktop that could result in arbitrary code execution in the context of the current user. Disclosed on September 8, 2026, it affects Photoshop 2025 versions up to and including 26.11.6, and Photoshop 2026 versions up to and including 27.6. Fixed versions are Photoshop 2025 26.11.7 and Photoshop 2026 27.7. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).

Technical details

The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound), where a calculation in Photoshop Desktop's file parsing logic can produce an integer overflow or wraparound, causing the resulting value to wrap to a very small or negative number. This can corrupt memory in a way that enables arbitrary code execution. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted malicious file. The attack complexity is low, meaning no special conditions beyond user interaction are needed to trigger the flaw (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high impact to confidentiality, integrity, and availability. An attacker who tricks a user into opening a malicious file could gain full control of the user's session, access sensitive data, modify files, or install malware. The scope is unchanged, meaning the impact is contained to the affected Photoshop process and the current user's privileges, but this is still sufficient for significant data theft or system compromise on the victim's machine (GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.226% (14th percentile), indicating a low near-term probability of exploitation. Exploitation is not automatable, as it requires user interaction to open a malicious file, which limits mass exploitation potential.

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted image or Photoshop-compatible file (e.g., PSD, TIFF, or other supported format) that contains malformed data designed to trigger an integer overflow in Photoshop's file parsing routines.
  2. Deliver the file: The attacker delivers the malicious file to the target via phishing email, malicious download link, shared network drive, or social engineering — convincing the victim to open the file in Adobe Photoshop Desktop.
  3. Trigger the overflow: When the victim opens the file, Photoshop's parsing logic processes the malformed data, causing an integer overflow or wraparound that corrupts heap or stack memory.
  4. Achieve code execution: The memory corruption is leveraged to redirect execution flow, allowing the attacker to execute arbitrary code in the context of the current user, potentially deploying a payload such as a reverse shell or malware dropper (GitHub Advisory, Adobe Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Photoshop Desktop process (e.g., cmd.exe, powershell.exe, bash, curl, wget) following the opening of an external file.
  • File System: Newly created or modified files in user temp directories, startup folders, or application data paths shortly after Photoshop opens an untrusted file; unexpected executables or scripts dropped on disk.
  • Network: Outbound network connections initiated by the Photoshop process to unknown or suspicious external IP addresses or domains.
  • Logs: Application crash logs or Windows Event Logs showing Photoshop access violations or heap corruption errors coinciding with file open events; security logs showing new process creation under the Photoshop parent process.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Photoshop 2025 26.11.7 and Photoshop 2026 27.7. Users should update immediately via the Creative Cloud desktop application. As an interim measure, users should avoid opening Photoshop files received from untrusted or unknown sources. Organizations can also consider implementing application whitelisting and monitoring Photoshop processes for anomalous child process creation (Adobe Advisory, GitHub Advisory).

Community reactions

The vulnerability was noted by the Center for Internet Security (CIS) in an advisory covering multiple Adobe product vulnerabilities patched in September 2026, highlighting the risk of arbitrary code execution (CIS Advisory). Security aggregators including BeyondMachines and The Hacker Wire covered Adobe's September 2026 patch release. Tenable published Nessus detection plugins (343848, 343849) for the vulnerability. No significant independent researcher commentary or social media controversy has been observed beyond routine patch-cycle coverage.

Additional resources


SourceThis report was generated using AI

Related Adobe Photoshop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76199HIGH8.6
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-82007HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-82006HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-82005HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026
CVE-2026-75863HIGH7.8
  • Adobe Photoshop logoAdobe Photoshop
  • cpe:2.3:a:adobe:photoshop
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management