High severity7.8NVD Advisory· Published Jul 14, 2026· Updated Jul 17, 2026
CVE-2026-48344
CVE-2026-48344
Description
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Affected products
2- cpe:2.3:a:adobe:creative_cloud_desktop_application:*:*:*:*:*:*:*:*Range: <=6.9.1.1
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/creative-cloud/apsb26-77.htmlnvdVendor Advisory
News mentions
1- Adobe C2pa Web: 15 Vulnerabilities in CAI Content Credentials Disclosed TogetherVypr Intelligence · Aug 11, 2026