Remote Code Execution in Adobe Photoshop (CVE‑2026‑75771) via DICOM JPEG‑LS Integer Overflow
What It Is — Adobe Photoshop contains an integer‑overflow flaw in its DICOM JPEG‑LS image parser. The bug can be triggered when a maliciously crafted DICOM file is opened, leading to arbitrary code execution in the context of the Photoshop process.
Exploitability — Remote exploitation is possible but requires user interaction (opening a malicious file). The CVSS 7.8 rating reflects high confidentiality, integrity, and availability impact. No public exploit code has been released.
Affected Products — Adobe Photoshop (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Vulnerability Management – Demonstrates the need for a documented, repeatable patch‑management process that can be evidenced to auditors.
- Continuous Monitoring – Highlights the value of automated asset discovery and version tracking to prove that all Photoshop installations are up‑to‑date.
- Defensible Audit Trail – Shows how maintaining remediation tickets and patch‑deployment logs satisfies multiple control objectives across frameworks (e.g., NIST CSF “Protect” and ISO 27001 “Asset Management”).
Recommended Actions
- Deploy Adobe’s September 2026 security update for Photoshop immediately.
- Verify installed versions across the enterprise using an inventory tool; remediate any out‑of‑date instances.
- Capture patch‑deployment evidence (e.g., SCCM logs, endpoint‑agent reports) and map it to the “Vulnerability Management” control objective.
- Enable file‑type filtering or application‑whitelisting to reduce the chance of users opening untrusted DICOM files.
- Monitor threat‑intel feeds for any emerging exploits targeting CVE‑2026‑75771.