ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability
Executive Summary
Adobe Photoshop is vulnerable to an integer overflow in the DCM JPEG-LS image parser that can lead to remote code execution. The flaw requires user interaction, such as opening a malicious file or visiting a malicious page. The Zero Day Initiative assigned CVE-2026-75771 and a CVSS score of 7.8.
Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-10T05:00:00+00:00 - Category: cves
Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.
"Time stays long enough for anyone who will use it."
— Leonardo da Vinci