Adobe disclosed CVE-2026-48388, a high-severity flaw in the Photoshop Installer caused by an uncontrolled search path element (CWE-427). The issue allows a local attacker to place a malicious DLL or library in a directory searched by the installer so that, when a victim runs the installer, attacker-controlled code is loaded and executed in the context of the current user. The vulnerability is not remotely exploitable on its own, but it does require user interaction and can become more serious when installations are performed with elevated privileges.
Advisories warn that the installer may search user-writable locations before legitimate Windows system directories, creating a classic DLL hijacking condition. Organizations are being urged to update to the latest Adobe Photoshop release containing the patched installer, obtain installers only from official Adobe sources, remove suspicious libraries from searchable paths, enforce application allowlisting and stricter DLL search-order controls, and use least-privilege accounts during software installation.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A high-severity uncontrolled search path element (DLL hijacking) vulnerability affecting the Adobe Photoshop Installer was disclosed as CVE-2026-48388. The flaw can allow arbitrary code execution in the context of the user running the installer if a malicious library is placed in a searched directory, and guidance was issued to update to a patched version and use trusted installation sources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.