.

Adobe Security Bulletin

Last updated on Aug 11, 2026

Security Update Available for Adobe Lightroom Classic | APSB26-94

Bulletin ID
Date published
Priority
ASPB26-94
August 11, 2026
3

Summary

Adobe has released a security update for Adobe Lightroom Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this updates.

Affected Versions

Product
Version
Platform
Lightroom Classic
15.4 and earlier
Windows

Solution

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app’s update mechanism. For more information, please reference this help page.

For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information.

Product
Version
Platform
Priority rating
Availability
Lightroom Classic
15.5
All
3

Vulnerability Details

Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVE Number
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary code execution
Critical
8.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48441
Deserialization of Untrusted Data (CWE-502)
Arbitrary code execution
Critical
8.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48397
Integer Overflow or Wraparound (CWE-190)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-47940
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48404
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48405
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48406
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48407
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48408
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48409
Out-of-bounds Write (CWE-787)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48410
Incorrect Authorization (CWE-863)
Arbitrary code execution
Critical
7.7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48447

Acknowledgments

Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:

  • Kieran (kaiksi) — CVE-2026-48441, CVE-2026-48397, CVE-2026-48447
  • yjdfy — CVE-2026-48404, CVE-2026-48405, CVE-2026-48406, CVE-2026-48407, CVE-2026-48408, CVE-2026-48409, CVE-2026-48410, CVE-2026-47940