Critical Remote Code Execution in Adobe Photoshop DCM JPEG Parsing (CVE‑2026‑75862)
What It Is — Adobe Photoshop contains an integer‑overflow flaw in its DICOM JPEG image parser. The bug can be triggered when a maliciously crafted image is opened or rendered, allowing an attacker to execute arbitrary code in the context of the Photoshop process.
Exploitability — The vulnerability requires user interaction (opening a malicious file or visiting a page that loads it). No public exploit code is known, but the CVSS 7.8 rating (AV:L/AC:L/PR:N/UI:R) reflects a high impact once the file is opened.
Affected Products — Adobe Photoshop (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Vulnerability Management – Demonstrates the need for continuous monitoring of vendor‑issued patches and evidence of timely remediation, a core control across SOC 2, ISO 27001, NIST CSF and others.
- Secure Configuration – Highlights the importance of validating that all client‑side software is hardened against parsing errors, supporting a defensible audit trail.
- Supply‑Chain Assurance – Even widely trusted creative tools can harbor critical bugs; maintaining proof of due‑diligence in third‑party software is a key trust signal for enterprise buyers.
Recommended Actions
- Deploy Adobe’s September 2026 security update (APS‑B26‑130) across all Photoshop installations.
- Verify patch rollout through your asset inventory and configuration management tools; capture remediation evidence for audit purposes.
- Update your vulnerability‑management process to include regular scans for parsing‑related flaws in third‑party media libraries.
- Document the remediation steps in your control evidence repository to satisfy control‑objective audits.