HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution in Adobe Photoshop (CVE‑2026‑75771) via DICOM JPEG‑LS Integer Overflow

Adobe Photoshop’s DICOM JPEG‑LS parser suffers an integer‑overflow bug (CVE‑2026‑75771) that can lead to remote code execution when a malicious file is opened. The flaw underscores the importance of robust vulnerability‑management controls and auditable patch‑deployment evidence for compliance readiness.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
zerodayinitiative.com

Remote Code Execution in Adobe Photoshop (CVE‑2026‑75771) via DICOM JPEG‑LS Integer Overflow

What It Is — Adobe Photoshop contains an integer‑overflow flaw in its DICOM JPEG‑LS image parser. The bug can be triggered when a maliciously crafted DICOM file is opened, leading to arbitrary code execution in the context of the Photoshop process.

Exploitability — Remote exploitation is possible but requires user interaction (opening a malicious file). The CVSS 7.8 rating reflects high confidentiality, integrity, and availability impact. No public exploit code has been released.

Affected Products — Adobe Photoshop (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – Demonstrates the need for a documented, repeatable patch‑management process that can be evidenced to auditors.
  • Continuous Monitoring – Highlights the value of automated asset discovery and version tracking to prove that all Photoshop installations are up‑to‑date.
  • Defensible Audit Trail – Shows how maintaining remediation tickets and patch‑deployment logs satisfies multiple control objectives across frameworks (e.g., NIST CSF “Protect” and ISO 27001 “Asset Management”).

Recommended Actions

  • Deploy Adobe’s September 2026 security update for Photoshop immediately.
  • Verify installed versions across the enterprise using an inventory tool; remediate any out‑of‑date instances.
  • Capture patch‑deployment evidence (e.g., SCCM logs, endpoint‑agent reports) and map it to the “Vulnerability Management” control objective.
  • Enable file‑type filtering or application‑whitelisting to reduce the chance of users opening untrusted DICOM files.
  • Monitor threat‑intel feeds for any emerging exploits targeting CVE‑2026‑75771.

Source: Adobe Security Advisory APS‑B26‑130

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-677/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →