Adobe Bridge
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Adobe Bridge.
Recent Adobe Bridge Security Advisories
| Advisory | Title | Published |
|---|---|---|
| APSB26-89 | Security Updates Available for Adobe Bridge | APSB26-89 | July 28, 2026 |
| APSB26-81 | Security Updates Available for Adobe Bridge | APSB26-81 | July 14, 2026 |
| APSB26-39 | Security Updates Available for Adobe Bridge | APSB26-39 | April 14, 2026 |
| APSB26-21 | Security Updates Available for Adobe Bridge | APSB26-21 | February 10, 2026 |
| APSB26-07 | Security Updates Available for Adobe Bridge | APSB26-07 | January 13, 2026 |
| APSB25-96 | Security Updates Available for Adobe Bridge | APSB25-96 | October 14, 2025 |
| APSB25-44 | Security Updates Available for Adobe Bridge | APSB25-44 | May 13, 2025 |
| APSB25-25 | Security Updates Available for Adobe Bridge | APSB25-25 | April 8, 2025 |
| APSB24-103 | Security Updates Available for Adobe Bridge | APSB24-103 | December 10, 2024 |
| APSB24-77 | Security Updates Available for Adobe Bridge | APSB24-77 | November 12, 2024 |
By the Year
In 2026 there have been 24 vulnerabilities in Adobe Bridge with an average score of 7.8 out of ten. Last year, in 2025 Bridge had 6 security vulnerabilities published. That is, 18 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.39.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 24 | 7.80 |
| 2025 | 6 | 7.42 |
| 2024 | 13 | 6.74 |
| 2023 | 12 | 6.46 |
| 2022 | 16 | 7.51 |
| 2021 | 4 | 7.80 |
| 2020 | 22 | 7.80 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Bridge vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Adobe Bridge Security Vulnerabilities
Adobe Bridge OOB Write Enables Arbitrary Code Exec
CVE-2026-48394
7.8 - High
- July 28, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge Path Traversal via Malicious File
CVE-2026-48374
7.8 - High
- July 28, 2026
Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Directory traversal
Adobe Bridge Untrusted Search Path CVE202648391
CVE-2026-48391
8.2 - High
- July 28, 2026
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Untrusted Path
Adobe Bridge OOB Write VULN Enables Arbitrary Code Execution
CVE-2026-48392
7.8 - High
- July 28, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge Improper Auth Priv Esc from Malicious File
CVE-2026-48390
8.2 - High
- July 28, 2026
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
AuthZ
Adobe Bridge OOB Write Arbitrary Code Exec
CVE-2026-48393
7.8 - High
- July 28, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge Untrusted Search Path Vulnerability Enables Arbitrary Code Execution
CVE-2026-48395
8.6 - High
- July 28, 2026
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Untrusted Path
Adobe Bridge Incorrect Auth Arbitrary Code Exec (CVE-2026-48396)
CVE-2026-48396
8.6 - High
- July 28, 2026
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
AuthZ
Untrusted Pointer Deref. in Adobe Bridge Enables RCE
CVE-2026-48340
7.8 - High
- July 14, 2026
Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Untrusted Pointer Dereference
Adobe Bridge OOB Write -> Arbitrary Code Execution
CVE-2026-48343
7.8 - High
- July 14, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge OOB Write Arbitrary Code Execution via Malicious File
CVE-2026-48311
7.8 - High
- July 14, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge Heap Buffer Overflow Enables User-Interactive Arbitrary Exec
CVE-2026-48339
7.8 - High
- July 14, 2026
Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Bridge: Integer Overflow Allows Code Exec via File
CVE-2026-48342
7.8 - High
- July 14, 2026
Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Bridge OOB Write => Arbitrary Exec via Malicious File
CVE-2026-48341
7.8 - High
- July 14, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge <16.0.2 Heap Buffer Overflow
CVE-2026-34630
7.8 - High
- April 14, 2026
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Bridge <16.0.2, <15.1.4: Heap Buffer Overflow CVE-2026-27312
CVE-2026-27312
7.8 - High
- April 14, 2026
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Bridge <=16.0.2 DIV0 DoS
CVE-2026-27222
5.5 - Medium
- April 14, 2026
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Divide By Zero
Adobe Bridge heap overflow 16.0.2/15.1.4 via malicious file
CVE-2026-27310
7.8 - High
- April 14, 2026
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Bridge <=16.0.2 Heap Overflow CVE-2026-27311
CVE-2026-27311
7.8 - High
- April 14, 2026
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Bridge Heap Buffer Overflow prior to 16.0.2 via malicious file
CVE-2026-27313
7.8 - High
- April 14, 2026
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Substance3D Stager UAF CVE-2026-27309 (3.1.6)
CVE-2026-27309
7.8 - High
- March 27, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Bridge < 16.0.1 OOB Write Allows Arbitrary Code Exec
CVE-2026-21346
7.8 - High
- February 10, 2026
Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Bridge 15.1.3/16.0.1 Integer Overflow/Wraparound => Remote Code Exec
CVE-2026-21347
7.8 - High
- February 10, 2026
Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Adobe Bridge <=16.0 Heap Overflow (arbitrary code exec)
CVE-2026-21283
7.8 - High
- January 13, 2026
Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Bridge Heap Buffer Overflow (CVE-2025-54268) v<15.1.1
CVE-2025-54268
7.8 - High
- October 15, 2025
Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Bridge <14.1.8/15.1.1 Heap Buffer Overflow (Sensitive Info Disclosure)
CVE-2025-54278
5.5 - Medium
- October 15, 2025
Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Integer Overflow in Bridge 15.0.3/14.1.6 Enables Arbitrary Code Execution
CVE-2025-43547
7.8 - High
- May 13, 2025
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Bridge <=15.0.3 CVE-2025-43546: Int Underflow Exploit
CVE-2025-43546
7.8 - High
- May 13, 2025
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Uninitialized Ptr Access in Bridge <=15.0.3/14.1.6 Enables Exec
CVE-2025-43545
7.8 - High
- May 13, 2025
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Access of Uninitialized Pointer
Adobe Bridge <=15.0.2 Heap Buffer Overflow (CVE-2025-27193)
CVE-2025-27193
7.8 - High
- April 08, 2025
Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Bridge Integer Underflow Arbitrary Code Execution Vulnerability
CVE-2024-53955
7.8 - High
- December 10, 2024
Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Out-of-Bounds Read Vulnerability in Adobe Bridge
CVE-2024-45147
5.5 - Medium
- November 12, 2024
Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Bridge NULL Pointer Dereference Vulnerability in File Parsing
CVE-2024-47458
5.5 - Medium
- November 12, 2024
Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NULL Pointer Dereference
Bridge < 14.1.1: OOB Write Arbitrary Exec (User Interaction)
CVE-2024-39386
7.8 - High
- August 14, 2024
Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Bridge 13.0.8/14.1.1 OOB Write Arbitrary Code Execution
CVE-2024-41840
7.8 - High
- August 14, 2024
Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge <=14.1.1 OOB Read Vulnerability (ASLR Bypass)
CVE-2024-39387
5.5 - Medium
- August 14, 2024
Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Bridge 14.1 OOB Read Disclosure (CVE-2024-34140)
CVE-2024-34140
5.5 - Medium
- July 09, 2024
Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Integer Overflow in Bridge (14.1) Enables Arbitrary Code Execution
CVE-2024-34139
7.8 - High
- July 09, 2024
Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Bridge <=14.0.2 OOB Read in file parsing may bypass ASLR
CVE-2024-20771
5.5 - Medium
- April 11, 2024
Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Bridge <13.0.5/14.0.1 OOB Write allows arbitrary code exec
CVE-2024-20756
7.8 - High
- March 18, 2024
Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Bridge 13.0.5/14.0.1 Use-After-Free Allows ACO via Malicious File
CVE-2024-20752
7.8 - High
- March 18, 2024
Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Heap Buffer Overflow in Bridge 13.0.5/14.0.1 Enables Arbitrary Code Exec
CVE-2024-20755
7.8 - High
- March 18, 2024
Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Bridge.NET OOB read <14.0.1, ASLR bypass
CVE-2024-20757
5.5 - Medium
- March 18, 2024
Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Bridge <13.0.4/14.0.0 Access of Uninitialized Pointer (ASLR Bypass)
CVE-2023-44329
5.5 - Medium
- November 16, 2023
Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Access of Uninitialized Pointer
Adobe Bridge UAF Leads to Memory Disclosure in v13.0.4/14.0.0
CVE-2023-44328
5.5 - Medium
- November 16, 2023
Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Bridge <=14.0.0: Uninitialized Pointer Disclosure
CVE-2023-44327
5.5 - Medium
- November 16, 2023
Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Access of Uninitialized Pointer
OOB Read in Adobe Bridge 12.0.4/13.0.3 Enables Sensitive Memory Disclosure
CVE-2023-38217
5.5 - Medium
- October 11, 2023
Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Bridge UAF in 12.0.4/13.0.3 leads to memory disclosure
CVE-2023-38216
5.5 - Medium
- October 11, 2023
Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Out-of-Bounds Write Arbitrary Code Exec in Adobe Bridge 12.0.3,13.0.1
CVE-2023-22229
7.8 - High
- February 17, 2023
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Bridge 12.0.3/13.0.1 OOB Read, ASLR Bypass
CVE-2023-21583
5.5 - Medium
- February 17, 2023
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Adobe Bridge or by Adobe? Click the Watch button to subscribe.