PatchSiren cyber security CVE debrief
CVE-2026-76199 Adobe CVE debrief
CVE-2026-76199 is a high-severity Uncontrolled Search Path Element vulnerability in Adobe Photoshop that could lead to arbitrary code execution. This issue requires user interaction, as a victim must open a malicious file. The vulnerability affects Photoshop versions 26.0 through 26.11.7 and 27.0 through 27.7. It is crucial for defenders to assess exposure and prioritize updates to prevent potential code execution in the context of the current user. The CVE record and NVD entry provide details on the vulnerability, including its high CVSS score of 8.6 and affected software versions.
- Vendor
- Adobe
- Product
- Photoshop
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for managing Adobe Photoshop installations, particularly in environments where users frequently open files from external sources, should assess exposure and prioritize updates.
Why it matters
CVE-2026-76199 is a high-severity vulnerability in Adobe Photoshop that requires immediate attention from defenders to prevent potential code execution.
- Potential arbitrary code execution in the context of the current user.
- Requires user interaction to open a malicious file.
- Affected versions of Photoshop need to be updated to prevent exploitation.
Technical summary
The vulnerability is caused by an Uncontrolled Search Path Element in Adobe Photoshop, which could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by tricking a victim into opening a malicious file. The vulnerability affects Photoshop versions 26.0 through 26.11.7 and 27.0 through 27.7. It is crucial for defenders to assess exposure and prioritize updates to prevent potential code execution. The CVE record and NVD entry provide details on the vulnerability, including its high CVSS score of 8.6 and affected software versions. Defenders should prioritize verifying and updating Adobe Photoshop installations to prevent potential code execution.
Defensive priority
Defenders should prioritize verifying and updating Adobe Photoshop installations to prevent potential code execution.
Recommended defensive actions
- Verify and update Adobe Photoshop installations to the latest version.
- Restrict user access to potentially vulnerable versions of Photoshop.
- Implement monitoring to detect potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its high CVSS score of 8.6 and affected software versions. The vulnerability is caused by an Uncontrolled Search Path Element in Adobe Photoshop, which could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by tricking a victim into opening a malicious file. The vulnerability affects Photoshop versions 26.0 through 26.11.7 and 27.0 through 27.7. There is limited information available on the 3
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76199 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76199
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76199 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76199
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/photoshop/apsb26-130.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.