HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in Adobe Photoshop DCM JPEG Parsing (CVE‑2026‑75862)

Adobe Photoshop’s DICOM JPEG parser suffers an integer‑overflow that can lead to remote code execution when a malicious image is opened. The flaw underscores the need for continuous patch monitoring and evidence‑based vulnerability management to meet audit requirements.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in Adobe Photoshop DCM JPEG Parsing (CVE‑2026‑75862)

What It Is — Adobe Photoshop contains an integer‑overflow flaw in its DICOM JPEG image parser. The bug can be triggered when a maliciously crafted image is opened or rendered, allowing an attacker to execute arbitrary code in the context of the Photoshop process.

Exploitability — The vulnerability requires user interaction (opening a malicious file or visiting a page that loads it). No public exploit code is known, but the CVSS 7.8 rating (AV:L/AC:L/PR:N/UI:R) reflects a high impact once the file is opened.

Affected Products — Adobe Photoshop (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – Demonstrates the need for continuous monitoring of vendor‑issued patches and evidence of timely remediation, a core control across SOC 2, ISO 27001, NIST CSF and others.
  • Secure Configuration – Highlights the importance of validating that all client‑side software is hardened against parsing errors, supporting a defensible audit trail.
  • Supply‑Chain Assurance – Even widely trusted creative tools can harbor critical bugs; maintaining proof of due‑diligence in third‑party software is a key trust signal for enterprise buyers.

Recommended Actions

  • Deploy Adobe’s September 2026 security update (APS‑B26‑130) across all Photoshop installations.
  • Verify patch rollout through your asset inventory and configuration management tools; capture remediation evidence for audit purposes.
  • Update your vulnerability‑management process to include regular scans for parsing‑related flaws in third‑party media libraries.
  • Document the remediation steps in your control evidence repository to satisfy control‑objective audits.

Source: Zero Day Initiative Advisory – ZDI‑26‑679

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-679/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →