Adobe Photoshop APSB26-130: Eight Critical Flaws Including Seven RCEs Patched

Adobe Photoshop APSB26-130 security update patching seven critical RCE vulnerabilities

Photoshop has received an uncommonly weighty patch in which nearly every remediated flaw leads to the execution of foreign code. Adobe has released update APSB26-130 for Photoshop 2025 and 2026 on both Windows and macOS. The bulletin addresses eight critical vulnerabilities: seven of them enable arbitrary code execution, while one permits the bypass of a security mechanism.

Four RCEs Rooted in Integer Overflow

Four of the remote code execution vulnerabilities stem from integer overflow: CVE-2026-82007, CVE-2026-75863, CVE-2026-75862, and CVE-2026-75771. Each received a CVSS 3.1 score of 7.8. The last three were reported to Adobe by Brandon Evans of TrendAI Zero Day Initiative; the first was discovered by a researcher under the pseudonym yjdfy.

Three More RCEs Tied to Memory Corruption

Three further remote code execution flaws arise from memory corruption. CVE-2026-82006, scored 7.8 on CVSS 3.1, triggers a heap-based buffer overflow and was reported by Jony (jony_juice). CVE-2026-75631 and CVE-2026-82005, also rated 7.8, involve out-of-bounds writes; the former was likewise credited to yjdfy. All seven vulnerabilities require user interaction; Adobe has not specified the precise file formats involved.

Past Photoshop vulnerabilities have enabled code execution through specially crafted PSD files, though there is no basis for applying that scenario directly to the current set of CVEs. APSB26-130 discloses only vulnerability classes and CVSS vectors. Consequently, the seven RCEs do not amount to a contactless network exploit: the published ratings indicate a local vector and mandatory user interaction.

The Highest-Scored Flaw: A Security Feature Bypass

The highest score in the bulletin belongs to CVE-2026-76199, rated 8.6 under CVSS 3.1, reported by Kieran (kaiksi). This flaw, arising from an uncontrolled search path element, allows the bypass of a security mechanism.

Affected Versions and Patching Guidance

The vulnerable versions are Photoshop 2026 version 27.6 and earlier, and Photoshop 2025 version 26.11.6 and earlier. The fixes are incorporated in versions 27.7 and 26.11.7 respectively. Adobe assigned this release a Priority 3 rating, reserved for products that have historically been infrequent targets of such attacks. As of September 8, the company was unaware of any instance of these eight vulnerabilities being exploited in the wild.

Adobe recommends that users update Photoshop via the Creative Cloud Desktop application. In managed enterprise environments, administrators may deploy the new builds through the Admin Console. Priority 3 does not conflict with the critical severity of the individual flaws: the priority scale gauges installation urgency in light of attack history, whereas the “Critical” designation describes the potential harm upon successful exploitation.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply