Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

cve CVE-2026-75862 1 source, 1 claim · Watch

NVD writes:
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. the claim

What it is to other things

affectsadobe/photoshop
NVD
affectsapple/macos
NVD
affectsmicrosoft/windows
NVD
made_byadobe
NVD
made_byapple
NVD
made_bymicrosoft
NVD

In words only, so not counted until a person confirms one:

affectsadobe/photoshop_2026
NVD says “Adobe · Photoshop 2026”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2026",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "27.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "27.7",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2025",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.11.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "26.11.7",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "51721C8F-1F6E-4A5B-AA7F-D849233CEA8A",
                "versionEndExcluding": "26.11.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2A0EC946-6C2F-47B6-9E5E-9BFCB0BAF24A",
                "versionEndExcluding": "27.7",
                "versionStartIncluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-75862",
    "lastModified": "2026-09-11T18:32:27.863",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-75862",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-09T04:27:30.477696Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T20:18:22.353",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/photoshop/apsb26-130.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDPhotoshop 2026
receipt
Source
NVD
Its words
Photoshop 2026
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCPhotoshop 2026
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2026",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "27.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "27.7",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2025",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.11.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "26.11.7",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "51721C8F-1F6E-4A5B-AA7F-D849233CEA8A",
                "versionEndExcluding": "26.11.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2A0EC946-6C2F-47B6-9E5E-9BFCB0BAF24A",
                "versionEndExcluding": "27.7",
                "versionStartIncluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-75862",
    "lastModified": "2026-09-11T18:32:27.863",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-75862",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-09T04:27:30.477696Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T20:18:22.353",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/photoshop/apsb26-130.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2026",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "27.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "27.7",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2025",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.11.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "26.11.7",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "51721C8F-1F6E-4A5B-AA7F-D849233CEA8A",
                "versionEndExcluding": "26.11.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2A0EC946-6C2F-47B6-9E5E-9BFCB0BAF24A",
                "versionEndExcluding": "27.7",
                "versionStartIncluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-75862",
    "lastModified": "2026-09-11T18:32:27.863",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-75862",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-09T04:27:30.477696Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T20:18:22.353",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/photoshop/apsb26-130.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDAdobe
receipt
Source
NVD
Its words
Adobe
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCAdobe
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2026",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "27.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "27.7",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "product": "Photoshop 2025",
            "vendor": "Adobe",
            "versions": [
              {
                "lessThanOrEqual": "26.11.6",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "26.11.7",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "psirt@adobe.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "51721C8F-1F6E-4A5B-AA7F-D849233CEA8A",
                "versionEndExcluding": "26.11.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2A0EC946-6C2F-47B6-9E5E-9BFCB0BAF24A",
                "versionEndExcluding": "27.7",
                "versionStartIncluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
                "vulnerable": false
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
      }
    ],
    "id": "CVE-2026-75862",
    "lastModified": "2026-09-11T18:32:27.863",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "psirt@adobe.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-75862",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-09T04:27:30.477696Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T20:18:22.353",
    "references": [
      {
        "source": "psirt@adobe.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://helpx.adobe.com/security/products/photoshop/apsb26-130.html"
      }
    ],
    "sourceIdentifier": "psirt@adobe.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "psirt@adobe.com",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
zetlyn/cve-nvd · 2026-09-08
cvss 7.8 product Photoshop 2026 status Analyzed vendor Adobe source