Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3254 articles · 211237 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-48388
adobe · adobe photoshop installer

Photoshop Installer | CWE-427: Uncontrolled Search Path Element

Description

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.

Affected Products

VendorProductVersions
adobeadobe photoshop installer0

References

  • https://cwe.mitre.org/data/definitions/427.html

Related News (2 articles)

Tier B
CERT-FR8d ago
Bulletin d'actualité CERTFR-2026-ACT-037 (31 août 2026)
→ No new info (linked only)
Tier C
VulDB41d ago
CVE-2026-48388 | Adobe Photoshop Installer untrusted search path
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-427
PublishedJul 28, 2026
Trending Score15
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-75650EXPKEV
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Trending: 140
HIGHCVE-2026-83959
Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
Trending: 17
HIGHCVE-2026-83961
ColdFusion | Improper Authentication (CWE-287)
Trending: 17
CRITICALCVE-2026-76197
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 13
CRITICALCVE-2026-76195
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026