Remote Code Execution in Adobe Photoshop (CVE‑2026‑75863) via DICOM Parsing Integer Overflow
What It Is — An integer‑overflow flaw in Adobe Photoshop’s DICOM image‑file parser allows a remote attacker to execute arbitrary code when a crafted file is opened or rendered.
Exploitability — CVSS 7.8 (High). Exploitation requires user interaction (opening a malicious file or visiting a malicious page); no public exploit code is known, but the vulnerability is actively exploitable.
Affected Products — Adobe Photoshop (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Underscores the need for a continuous vulnerability‑management control that identifies, assesses, and remediates third‑party software flaws.
- Timely patch deployment and retained evidence satisfy audit‑ready control objectives across multiple frameworks (e.g., NIST CSF, ISO 27001).
- Reinforces the requirement for ongoing monitoring of vendor‑supplied components to maintain a defensible security posture for customers and partners.
Recommended Actions
- Apply Adobe’s September 2026 security update to every Photoshop installation immediately.
- Verify patch rollout through automated asset‑inventory and patch‑management tools; archive proof for audit purposes.
- Extend secure‑development or code‑review checklists to include validation of image‑parsing logic for future integrations.
Source: Zero Day Initiative Advisory