Description
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw within Adobe Bridge permits an attacker to run arbitrary code in the context of the user who opens a crafted file. This flaw can compromise confidentiality, integrity, and availability by allowing the execution of malicious code with the victim’s privileges.

Affected Systems

Adobe Bridge produced by Adobe is affected; the vulnerability applies to all current releases prior to the fix stated in the Adobe security bulletin linked in the references.

Risk and Exploitability

With a CVSS score of 7.8 the flaw is high severity, yet the EPSS score is under 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and an attacker must persuade a user to open a malicious file, making user interaction a prerequisite for exploitation.

Generated by OpenCVE AI on August 3, 2026 at 14:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Bridge update provided in the security bulletin at https://helpx.adobe.com/security/products/bridge/apsb26-89.html to eliminate the out‑of‑bounds write flaw.
  • Configure the operating environment to refuse automatic execution of untrusted files (e.g., enable Windows SmartScreen or macOS Gatekeeper).
  • Adopt application whitelisting or sandboxing to restrict Adobe Bridge from executing code that has not been approved by the enterprise security policy.

Generated by OpenCVE AI on August 3, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T03:56:05.714Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48394

cve-icon Vulnrichment

Updated: 2026-07-28T18:47:07.603Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.627

Modified: 2026-08-03T13:37:03.160

Link: CVE-2026-48394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses