CVE-2026-48272 – Adobe Creative Cloud Desktop

CVSS 7.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“Trusted desktop software can become an attack path when execution controls break down.”

Adobe Creative Cloud Desktop addresses two high-severity vulnerabilities that could result in arbitrary code execution in the context of the current user. The vulnerabilities include an uncontrolled search path element and a time-of-check time-of-use (TOCTOU) race condition. Neither vulnerability requires user interaction, although successful exploitation depends on conditions beyond the attacker’s control.

CVE-2026-48272 has a CVSS score of 7.8, High severity. CVE-2026-48344 has a CVSS score of 7.8, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Adobe Creative Cloud Desktop Application
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-427
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.