PatchSiren cyber security CVE debrief
CVE-2026-27289 Adobe CVE debrief
Adobe Photoshop Desktop versions 27.4 and earlier contain an out-of-bounds read vulnerability (CWE-125) triggered when parsing a crafted file. The flaw allows a read past the end of an allocated memory structure, which an attacker could leverage to achieve code execution in the context of the current user. Successful exploitation requires user interaction—the victim must open a malicious file. The vulnerability was published in the NVD on April 14, 2026, and the record was last modified on June 1, 2026. Adobe has addressed this issue in security bulletin APSB26-40.
- Vendor
- Adobe
- Product
- Photoshop Desktop
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-14
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-04-14
- Advisory updated
- 2026-08-28
Who should care
Organizations using Adobe Photoshop Desktop in creative workflows, particularly those where users receive files from external clients, contractors, or public sources. Security teams responsible for endpoint protection and software update management in design, marketing, and media production environments.
Technical summary
The vulnerability is an out-of-bounds read (CWE-125) in Photoshop Desktop's file parsing logic. When processing a crafted file, the application reads beyond allocated memory boundaries. This memory safety defect can be exploited to achieve arbitrary code execution under the current user's privileges. The attack requires social engineering to convince a victim to open a malicious file. The local attack vector and user interaction requirement limit but do not eliminate the threat, particularly in environments where users routinely exchange creative assets.
Defensive priority
HIGH
Recommended defensive actions
- Update Adobe Photoshop Desktop to version 27.5 or later as specified in Adobe security bulletin APSB26-40.
- Implement application control policies to restrict execution of untrusted Photoshop files (.psd, .psb, and other supported formats).
- Train users to avoid opening Photoshop files from untrusted sources, including email attachments and unsolicited downloads.
- Consider enabling protected view or sandboxing features where available for document-opening workflows.
- Monitor for anomalous Photoshop process behavior that may indicate attempted exploitation of parsing vulnerabilities.
Evidence notes
The vulnerability affects Photoshop Desktop versions from 27.0 up to but not including 27.5, per CPE criteria in the NVD record. The CVSS vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates local attack vector, low attack complexity, no privileges required, user interaction required, and high impacts to confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-27289 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-27289
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-27289 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27289
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/photoshop/apsb26-40.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.