ThreatCluster

Multiple Adobe Photoshop Vulnerabilities Allow Remote Code Execution

First seen 10 Sep 2026, 13:46 UTC Zerodayinitiativewww.cve.org 45

Article Content

Browse articles
ThreatCluster

Three vulnerabilities have been identified in Adobe Photoshop, allowing remote attackers to execute arbitrary code. These vulnerabilities, ZDI-26-679, ZDI-26-678, and ZDI-26-677, involve integer overflow issues during the parsing of DICOM image data. User interaction is required for exploitation, as victims must open a malicious file or visit a malicious webpage. Adobe has released updates to address these vulnerabilities. The vulnerabilities were reported to Adobe between June 15 and June 26, 2026, with public advisories released on September 10, 2026. The flaws affect all affected installations of Adobe Photoshop. Security professionals are urged to apply the updates promptly to mitigate risks.

Key Points: • Three vulnerabilities in Adobe Photoshop allow remote code execution. • User interaction is required for exploitation via malicious files or pages. • Adobe has issued updates to address these vulnerabilities.

Ask AI about this cluster

Timeline

2026-06-15
Vulnerability ZDI-26-678 reported
Adobe was notified of the integer overflow vulnerability in Photoshop related to DICOM file parsing.
Zerodayinitiative
2026-06-26
Vulnerability ZDI-26-679 reported
Another integer overflow vulnerability in JPEG image parsing was reported to Adobe.
Zerodayinitiative
2026-09-10
Public advisory released for multiple vulnerabilities
Adobe coordinated the public release of advisories for vulnerabilities ZDI-26-679, ZDI-26-678, and ZDI-26-677.
Zerodayinitiative