Adobe Photoshop Desktop patches eight code-execution flaws
Adobe fixed eight memory-corruption vulnerabilities in Photoshop Desktop that allow code execution when opening malicious files.
NCSC-NL published an advisory detailing eight vulnerabilities patched by Adobe in Photoshop Desktop, including heap-based buffer overflow, integer overflow/wraparound, uncontrolled search path element, and out-of-bounds write issues. These flaws reside in the handling of specially crafted files opened within the application. An attacker who convinces a user to open a maliciously crafted file could achieve code execution with the privileges of the user running Photoshop, via memory corruption and overwriting of critical data structures.
CVSS scores range from 7.8 to 8.6, indicating high-severity local/client-side exploitation risk rather than remote, unauthenticated compromise. There is no indication in the advisory of active exploitation in the wild; this is a standard vendor patch disclosure. Adobe has released updates addressing all eight CVEs, and NCSC-NL recommends applying them. Defenders should prioritize patching Photoshop Desktop installations, particularly in creative, media, and design-heavy environments where untrusted file exchange (e.g., PSD files from external sources) is common, and consider user awareness around opening files from unverified sources.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0360.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free