Description
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in Adobe Bridge that allows a malformed file to corrupt memory during processing. If exploited, the crash can pivot to arbitrary code execution running with the current user’s privileges, a classic instance of CWE‑787. The flaw requires an attacker to supply a crafted file and for the victim to open it, so the attack vector hinges on user interaction and malicious file handling.

Affected Systems

Adobe offers the affected product as Adobe Bridge. The CVE does not specify which exact releases are vulnerable, so any version of Bridge that has not received the patch disclosed in Adobe’s security advisory (APSb26‑89) should be considered at risk. System administrators should verify the installed Bridge version against Adobe’s published advisory and apply the update if it meets the vulnerability criteria.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑impact vulnerability with a good exploitation potential, yet the EPSS score of less than 1% suggests that, at the time of analysis, the likelihood of real‑world exploitation was low. Adobe has not listed this issue in the CISA KEV catalog, further implying that widespread attacks are not yet documented. Nevertheless, because the flaw can enable remote code execution once a user opens a malicious file, the risk is significant for environments where users have the ability to download or receive attachments from unknown or untrusted sources. The attack requires user interaction, but should a user open a crafted file, the compromise can occur immediately with no further access required.

Generated by OpenCVE AI on August 3, 2026 at 14:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Bridge to the version released in Adobe’s safety advisory APSb26‑89, which contains the fix for the out‑of‑bounds write.
  • Enable antivirus or DLP scanning on incoming attachments to detect malformed or malicious files before they are opened with Adobe Bridge.
  • Conduct user awareness training to warn operators against opening files from untrusted senders or sources, and enforce a policy that requires verification before any file is processed by Bridge.

Generated by OpenCVE AI on August 3, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T03:56:04.851Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48393

cve-icon Vulnrichment

Updated: 2026-07-28T19:37:05.666Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.503

Modified: 2026-08-03T13:37:00.723

Link: CVE-2026-48393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses