Bridge Adobe Bridge

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Adobe Bridge.

Recent Adobe Bridge Security Advisories

Advisory Title Published
APSB26-89 Security Updates Available for Adobe Bridge | APSB26-89 July 28, 2026
APSB26-81 Security Updates Available for Adobe Bridge | APSB26-81 July 14, 2026
APSB26-39 Security Updates Available for Adobe Bridge | APSB26-39 April 14, 2026
APSB26-21 Security Updates Available for Adobe Bridge | APSB26-21 February 10, 2026
APSB26-07 Security Updates Available for Adobe Bridge | APSB26-07 January 13, 2026
APSB25-96 Security Updates Available for Adobe Bridge | APSB25-96 October 14, 2025
APSB25-44 Security Updates Available for Adobe Bridge | APSB25-44 May 13, 2025
APSB25-25 Security Updates Available for Adobe Bridge | APSB25-25 April 8, 2025
APSB24-103 Security Updates Available for Adobe Bridge | APSB24-103 December 10, 2024
APSB24-77 Security Updates Available for Adobe Bridge | APSB24-77 November 12, 2024

By the Year

In 2026 there have been 24 vulnerabilities in Adobe Bridge with an average score of 7.8 out of ten. Last year, in 2025 Bridge had 6 security vulnerabilities published. That is, 18 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.39.




Year Vulnerabilities Average Score
2026 24 7.80
2025 6 7.42
2024 13 6.74
2023 12 6.46
2022 16 7.51
2021 4 7.80
2020 22 7.80
2019 2 0.00

It may take a day or so for new Bridge vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Adobe Bridge Security Vulnerabilities

Adobe Bridge OOB Write Enables Arbitrary Code Exec
CVE-2026-48394 7.8 - High - July 28, 2026

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge Path Traversal via Malicious File
CVE-2026-48374 7.8 - High - July 28, 2026

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Directory traversal

Adobe Bridge Untrusted Search Path CVE202648391
CVE-2026-48391 8.2 - High - July 28, 2026

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Untrusted Path

Adobe Bridge OOB Write VULN Enables Arbitrary Code Execution
CVE-2026-48392 7.8 - High - July 28, 2026

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge Improper Auth Priv Esc from Malicious File
CVE-2026-48390 8.2 - High - July 28, 2026

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

AuthZ

Adobe Bridge OOB Write Arbitrary Code Exec
CVE-2026-48393 7.8 - High - July 28, 2026

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge Untrusted Search Path Vulnerability Enables Arbitrary Code Execution
CVE-2026-48395 8.6 - High - July 28, 2026

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Untrusted Path

Adobe Bridge Incorrect Auth Arbitrary Code Exec (CVE-2026-48396)
CVE-2026-48396 8.6 - High - July 28, 2026

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

AuthZ

Untrusted Pointer Deref. in Adobe Bridge Enables RCE
CVE-2026-48340 7.8 - High - July 14, 2026

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Untrusted Pointer Dereference

Adobe Bridge OOB Write -> Arbitrary Code Execution
CVE-2026-48343 7.8 - High - July 14, 2026

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge OOB Write Arbitrary Code Execution via Malicious File
CVE-2026-48311 7.8 - High - July 14, 2026

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge Heap Buffer Overflow Enables User-Interactive Arbitrary Exec
CVE-2026-48339 7.8 - High - July 14, 2026

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge: Integer Overflow Allows Code Exec via File
CVE-2026-48342 7.8 - High - July 14, 2026

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Bridge OOB Write => Arbitrary Exec via Malicious File
CVE-2026-48341 7.8 - High - July 14, 2026

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <16.0.2 Heap Buffer Overflow
CVE-2026-34630 7.8 - High - April 14, 2026

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge <16.0.2, <15.1.4: Heap Buffer Overflow CVE-2026-27312
CVE-2026-27312 7.8 - High - April 14, 2026

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge <=16.0.2 DIV0 DoS
CVE-2026-27222 5.5 - Medium - April 14, 2026

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Divide By Zero

Adobe Bridge heap overflow 16.0.2/15.1.4 via malicious file
CVE-2026-27310 7.8 - High - April 14, 2026

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge <=16.0.2 Heap Overflow CVE-2026-27311
CVE-2026-27311 7.8 - High - April 14, 2026

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge Heap Buffer Overflow prior to 16.0.2 via malicious file
CVE-2026-27313 7.8 - High - April 14, 2026

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Substance3D Stager UAF CVE-2026-27309 (3.1.6)
CVE-2026-27309 7.8 - High - March 27, 2026

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Bridge < 16.0.1 OOB Write Allows Arbitrary Code Exec
CVE-2026-21346 7.8 - High - February 10, 2026

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge 15.1.3/16.0.1 Integer Overflow/Wraparound => Remote Code Exec
CVE-2026-21347 7.8 - High - February 10, 2026

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Adobe Bridge <=16.0 Heap Overflow (arbitrary code exec)
CVE-2026-21283 7.8 - High - January 13, 2026

Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Bridge Heap Buffer Overflow (CVE-2025-54268) v<15.1.1
CVE-2025-54268 7.8 - High - October 15, 2025

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Bridge <14.1.8/15.1.1 Heap Buffer Overflow (Sensitive Info Disclosure)
CVE-2025-54278 5.5 - Medium - October 15, 2025

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Integer Overflow in Bridge 15.0.3/14.1.6 Enables Arbitrary Code Execution
CVE-2025-43547 7.8 - High - May 13, 2025

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Bridge <=15.0.3 CVE-2025-43546: Int Underflow Exploit
CVE-2025-43546 7.8 - High - May 13, 2025

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Uninitialized Ptr Access in Bridge <=15.0.3/14.1.6 Enables Exec
CVE-2025-43545 7.8 - High - May 13, 2025

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Adobe Bridge <=15.0.2 Heap Buffer Overflow (CVE-2025-27193)
CVE-2025-27193 7.8 - High - April 08, 2025

Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge Integer Underflow Arbitrary Code Execution Vulnerability
CVE-2024-53955 7.8 - High - December 10, 2024

Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Out-of-Bounds Read Vulnerability in Adobe Bridge
CVE-2024-45147 5.5 - Medium - November 12, 2024

Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Bridge NULL Pointer Dereference Vulnerability in File Parsing
CVE-2024-47458 5.5 - Medium - November 12, 2024

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NULL Pointer Dereference

Bridge < 14.1.1: OOB Write Arbitrary Exec (User Interaction)
CVE-2024-39386 7.8 - High - August 14, 2024

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge 13.0.8/14.1.1 OOB Write Arbitrary Code Execution
CVE-2024-41840 7.8 - High - August 14, 2024

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <=14.1.1 OOB Read Vulnerability (ASLR Bypass)
CVE-2024-39387 5.5 - Medium - August 14, 2024

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge 14.1 OOB Read Disclosure (CVE-2024-34140)
CVE-2024-34140 5.5 - Medium - July 09, 2024

Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Integer Overflow in Bridge (14.1) Enables Arbitrary Code Execution
CVE-2024-34139 7.8 - High - July 09, 2024

Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Bridge <=14.0.2 OOB Read in file parsing may bypass ASLR
CVE-2024-20771 5.5 - Medium - April 11, 2024

Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Bridge <13.0.5/14.0.1 OOB Write allows arbitrary code exec
CVE-2024-20756 7.8 - High - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge 13.0.5/14.0.1 Use-After-Free Allows ACO via Malicious File
CVE-2024-20752 7.8 - High - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Heap Buffer Overflow in Bridge 13.0.5/14.0.1 Enables Arbitrary Code Exec
CVE-2024-20755 7.8 - High - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge.NET OOB read <14.0.1, ASLR bypass
CVE-2024-20757 5.5 - Medium - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge <13.0.4/14.0.0 Access of Uninitialized Pointer (ASLR Bypass)
CVE-2023-44329 5.5 - Medium - November 16, 2023

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Adobe Bridge UAF Leads to Memory Disclosure in v13.0.4/14.0.0
CVE-2023-44328 5.5 - Medium - November 16, 2023

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Bridge <=14.0.0: Uninitialized Pointer Disclosure
CVE-2023-44327 5.5 - Medium - November 16, 2023

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

OOB Read in Adobe Bridge 12.0.4/13.0.3 Enables Sensitive Memory Disclosure
CVE-2023-38217 5.5 - Medium - October 11, 2023

Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge UAF in 12.0.4/13.0.3 leads to memory disclosure
CVE-2023-38216 5.5 - Medium - October 11, 2023

Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Out-of-Bounds Write Arbitrary Code Exec in Adobe Bridge 12.0.3,13.0.1
CVE-2023-22229 7.8 - High - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge 12.0.3/13.0.1 OOB Read, ASLR Bypass
CVE-2023-21583 5.5 - Medium - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Adobe Bridge or by Adobe? Click the Watch button to subscribe.

Adobe
Vendor

Adobe Bridge
Product

subscribe