# Adobe Photoshop Desktop patches eight code-execution flaws

Published: 2026-09-09 · Severity: routine · Sectors: media, technology
Canonical: https://vorant.io/reports/69f3595f-5272-571f-9b89-d83384cf2533/adobe-photoshop-desktop-patches-eight-code-execution-flaws

> Adobe fixed eight memory-corruption vulnerabilities in Photoshop Desktop that allow code execution when opening malicious files.

NCSC-NL published an advisory detailing eight vulnerabilities patched by Adobe in Photoshop Desktop, including heap-based buffer overflow, integer overflow/wraparound, uncontrolled search path element, and out-of-bounds write issues. These flaws reside in the handling of specially crafted files opened within the application. An attacker who convinces a user to open a maliciously crafted file could achieve code execution with the privileges of the user running Photoshop, via memory corruption and overwriting of critical data structures.

CVSS scores range from 7.8 to 8.6, indicating high-severity local/client-side exploitation risk rather than remote, unauthenticated compromise. There is no indication in the advisory of active exploitation in the wild; this is a standard vendor patch disclosure. Adobe has released updates addressing all eight CVEs, and NCSC-NL recommends applying them. Defenders should prioritize patching Photoshop Desktop installations, particularly in creative, media, and design-heavy environments where untrusted file exchange (e.g., PSD files from external sources) is common, and consider user awareness around opening files from unverified sources.

## Mentioned in this report

- Vulnerabilities: CVE-2026-75631, CVE-2026-75771, CVE-2026-75862, CVE-2026-75863, CVE-2026-76199, CVE-2026-82005, CVE-2026-82006, CVE-2026-82007

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0360.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/69f3595f-5272-571f-9b89-d83384cf2533/adobe-photoshop-desktop-patches-eight-code-execution-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
