Junglewise Threat Intelligence

CVE-2026-82007: Adobe Photoshop Desktop integer overflow vulnerability

CVE-2026-82007 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Adobe Photoshop Desktop. Vendors: Adobe.

Executive brief

Photoshop Desktop contains an integer overflow vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires a victim to open a malicious file, making it a practical attack vector for delivering malware or gaining unauthorized access to a user's system.

Technical details

This is an integer overflow or wraparound vulnerability in Adobe Photoshop Desktop that can be exploited to achieve arbitrary code execution in the context of the current user. The vulnerability requires user interaction—specifically, the victim must open a crafted malicious file. The attack vector is local (file-based), and no authentication is required beyond the ability to trick a user into opening the malicious file. An attacker who successfully exploits this can execute arbitrary code with the same privileges as the user running Photoshop.

Affected products

  • Adobe Photoshop Desktop

Timeline

  • 2026-09-08: disclosed

References

Related threats