Description
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Bridge contains an out‑of‑bounds write flaw that can be exploited to execute arbitrary code within the current user’s context. The vulnerability is classified as CWE‑787 and would allow a malicious actor to run arbitrary instructions on a system when a user opens a crafted file.

Affected Systems

The affected product is Adobe Bridge. No specific version information was provided in the advisory, but all installations of Bridge may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score for this issue is 7.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, meaning a victim must open a malicious file; an attacker could supply such a file via email, download, or physical media. If exploited, the attacker would gain the privileges of the current user and could compromise the host system or move laterally within a network.

Generated by OpenCVE AI on September 22, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Bridge update as detailed in the Adobe security advisory.
  • Restrict Bridge operations to trusted files only, e.g., configure file handling permissions or use a sandbox.
  • If an immediate patch is not available, consider disabling Bridge until a corrective update is applied.

Generated by OpenCVE AI on September 22, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:14.782Z

Reserved: 2026-08-18T01:29:54.616Z

Link: CVE-2026-75663

cve-icon Vulnrichment

Updated: 2026-09-22T19:09:32.375Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:45.750

Modified: 2026-09-23T04:17:44.943

Link: CVE-2026-75663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:00:08Z

Weaknesses