Description
Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote code execution via stack overflow
Action: Patch Now
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow that can be triggered by opening a malicious file in Adobe Bridge. Exploitation leads to arbitrary code execution in the context of the current user, giving an attacker the same privileges as the victim. The weakness involves improper bounds checking during file processing, corresponding to CWE‑121.

Affected Systems

Adobe Bridge installations are affected. No specific version information is disclosed in the advisory; any deployment of Adobe Bridge remains at risk until a patch that addresses the buffer overflow is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, and the vulnerability requires user interaction to be exploited. Because the EPSS score is not provided, the likelihood of exploitation cannot be quantified, but the presence of a buffer overflow and the need for a user to open a file implies that the attack surface is limited to users who permit opening potentially malicious content. The vulnerability is not listed in the CISA KEV catalog, yet it remains a serious risk due to the potential for privileged code execution.

Generated by OpenCVE AI on September 22, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Bridge update that fixes the stack‑based buffer overflow.
  • Until the patch is available, refrain from opening any untrusted or suspicious files in Adobe Bridge.
  • Keep abreast of Adobe security advisories for any updates and monitor installations for signs of compromise.

Generated by OpenCVE AI on September 22, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Stack-based Buffer Overflow (CWE-121)
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:12.591Z

Reserved: 2026-08-18T01:29:54.617Z

Link: CVE-2026-75676

cve-icon Vulnrichment

Updated: 2026-09-22T19:22:40.570Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:46.037

Modified: 2026-09-23T04:17:45.263

Link: CVE-2026-75676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:00:08Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow