August 2026 Patch TuesdayAPSB26-94Normal patch window

Adobe · APSB26-94

Linked CVE review

Update Adobe Lightroom Classic to the fixed Adobe release

Linked CVEs
11
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
8.6
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
11 of 11 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-48397 Scheduled assessment
Lightroom Classic | Deserialization of Untrusted Data (CWE-502)

Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

8.6 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.97% · 60.8th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-47940 Scheduled assessment
Lightroom Classic | Integer Overflow or Wraparound (CWE-190)

Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.31% · 22.1th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48441 Scheduled assessment
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

8.6 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.31% · 21.3th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48404 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48405 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48406 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48407 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48408 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48409 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48410 Scheduled assessment
Lightroom Classic | Out-of-bounds Write (CWE-787)

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 15.7th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5
CVE-2026-48447 Scheduled assessment
Lightroom Classic | Incorrect Authorization (CWE-863)

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

7.7 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.22% · 11.1th percentileForecast date: 2026-10-05LOCAL · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 15.5