Bridge Adobe Bridge

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Adobe Bridge.

Recent Adobe Bridge Security Advisories

Advisory Title Published
APSB26-21 Security Updates Available for Adobe Bridge | APSB26-21 February 10, 2026
APSB26-07 Security Updates Available for Adobe Bridge | APSB26-07 January 13, 2026
APSB25-96 Security Updates Available for Adobe Bridge | APSB25-96 October 14, 2025
APSB25-44 Security Updates Available for Adobe Bridge | APSB25-44 May 13, 2025
APSB25-25 Security Updates Available for Adobe Bridge | APSB25-25 April 8, 2025
APSB24-103 Security Updates Available for Adobe Bridge | APSB24-103 December 10, 2024
APSB24-77 Security Updates Available for Adobe Bridge | APSB24-77 November 12, 2024
APSB24-59 Security Updates Available for Adobe Bridge | APSB24-59 August 13, 2024
APSB24-51 Security Updates Available for Adobe Bridge | APSB24-51 July 9, 2024
APSB24-24 Security Updates Available for Adobe Bridge | APSB24-24 April 9, 2024

By the Year

In 2026 there have been 3 vulnerabilities in Adobe Bridge with an average score of 7.8 out of ten. Last year, in 2025 Bridge had 6 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Bridge in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.




Year Vulnerabilities Average Score
2026 3 7.80
2025 6 7.42
2024 13 6.74
2023 12 6.46
2022 16 7.51
2021 2 7.80
2020 17 7.80

It may take a day or so for new Bridge vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Adobe Bridge Security Vulnerabilities

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability
CVE-2026-21346 7.8 - High - February 10, 2026

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability
CVE-2026-21347 7.8 - High - February 10, 2026

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability
CVE-2026-21283 7.8 - High - January 13, 2026

Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Bridge Heap Buffer Overflow (CVE-2025-54268) v<15.1.1
CVE-2025-54268 7.8 - High - October 15, 2025

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Bridge <14.1.8/15.1.1 Heap Buffer Overflow (Sensitive Info Disclosure)
CVE-2025-54278 5.5 - Medium - October 15, 2025

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Uninitialized Ptr Access in Bridge <=15.0.3/14.1.6 Enables Exec
CVE-2025-43545 7.8 - High - May 13, 2025

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Bridge <=15.0.3 CVE-2025-43546: Int Underflow Exploit
CVE-2025-43546 7.8 - High - May 13, 2025

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Integer Overflow in Bridge 15.0.3/14.1.6 Enables Arbitrary Code Execution
CVE-2025-43547 7.8 - High - May 13, 2025

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Adobe Bridge <=15.0.2 Heap Buffer Overflow (CVE-2025-27193)
CVE-2025-27193 7.8 - High - April 08, 2025

Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge Integer Underflow Arbitrary Code Execution Vulnerability
CVE-2024-53955 7.8 - High - December 10, 2024

Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer underflow

Out-of-Bounds Read Vulnerability in Adobe Bridge
CVE-2024-45147 5.5 - Medium - November 12, 2024

Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Bridge NULL Pointer Dereference Vulnerability in File Parsing
CVE-2024-47458 5.5 - Medium - November 12, 2024

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NULL Pointer Dereference

Bridge 13.0.8/14.1.1 OOB Write Arbitrary Code Execution
CVE-2024-41840 7.8 - High - August 14, 2024

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <=14.1.1 OOB Read Vulnerability (ASLR Bypass)
CVE-2024-39387 5.5 - Medium - August 14, 2024

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Bridge < 14.1.1: OOB Write Arbitrary Exec (User Interaction)
CVE-2024-39386 7.8 - High - August 14, 2024

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge 14.1 OOB Read Disclosure (CVE-2024-34140)
CVE-2024-34140 5.5 - Medium - July 09, 2024

Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Integer Overflow in Bridge (14.1) Enables Arbitrary Code Execution
CVE-2024-34139 7.8 - High - July 09, 2024

Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Integer Overflow or Wraparound

Bridge <=14.0.2 OOB Read in file parsing may bypass ASLR
CVE-2024-20771 5.5 - Medium - April 11, 2024

Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Bridge 13.0.5/14.0.1 Use-After-Free Allows ACO via Malicious File
CVE-2024-20752 7.8 - High - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Heap Buffer Overflow in Bridge 13.0.5/14.0.1 Enables Arbitrary Code Exec
CVE-2024-20755 7.8 - High - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge <13.0.5/14.0.1 OOB Write allows arbitrary code exec
CVE-2024-20756 7.8 - High - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Bridge.NET OOB read <14.0.1, ASLR bypass
CVE-2024-20757 5.5 - Medium - March 18, 2024

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge UAF Leads to Memory Disclosure in v13.0.4/14.0.0
CVE-2023-44328 5.5 - Medium - November 16, 2023

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Bridge <13.0.4/14.0.0 Access of Uninitialized Pointer (ASLR Bypass)
CVE-2023-44329 5.5 - Medium - November 16, 2023

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

Adobe Bridge <=14.0.0: Uninitialized Pointer Disclosure
CVE-2023-44327 5.5 - Medium - November 16, 2023

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Access of Uninitialized Pointer

OOB Read in Adobe Bridge 12.0.4/13.0.3 Enables Sensitive Memory Disclosure
CVE-2023-38217 5.5 - Medium - October 11, 2023

Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge UAF in 12.0.4/13.0.3 leads to memory disclosure
CVE-2023-38216 5.5 - Medium - October 11, 2023

Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Bridge 12.0.3/13.0.1 OOB Read, ASLR Bypass
CVE-2023-21583 5.5 - Medium - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge v12.0.3 & v13.0.1: Stack-Based Buffer Overflow
CVE-2023-22226 7.8 - High - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge AB Out-of-Bounds Write Before 12.0.3/13.0.1
CVE-2023-22227 7.8 - High - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <13 Improper Input Validation RCE
CVE-2023-22228 7.8 - High - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Improper Input Validation

Out-of-Bounds Write Arbitrary Code Exec in Adobe Bridge 12.0.3,13.0.1
CVE-2023-22229 7.8 - High - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge 12.0.3/13.0.1 OOB Write Arbitrary Code Exec
CVE-2023-22230 7.8 - High - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <13.0.1 OOBR Memory Disclosure via Malicious File
CVE-2023-22231 5.5 - Medium - February 17, 2023

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

AdobeBridge UAF in 12.0.2/11.1.3 Exposes Sensitive Memory
CVE-2022-35709 5.5 - Medium - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Out-of-Bounds Write in Adobe Bridge 12.0.2/11.1.3 Enables RCE
CVE-2022-35699 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <=12.0.2 OOB Write Arbitrary Local Code Exec
CVE-2022-35700 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge <=12 OOB Write -> Arbitrary Exec (CVE-2022-35701)
CVE-2022-35701 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Memory Corruption

Adobe Bridge OOB Read v12.0.2 and v11.1.3 Leading to Code Exec
CVE-2022-35702 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge OOB Read CVE-2022-35703 (pre-12.0.3, pre-11.1.4)
CVE-2022-35703 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge UA-FREE <12.0.3 Arbitrary Code Exec
CVE-2022-35704 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Bridge 12 OOB Read Vulnerability (before 12.0.2)
CVE-2022-35705 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge 12.0 Heap-based Buffer Overflow CVE-2022-35706
CVE-2022-35706 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge OOB Read ( 12.0.2)
CVE-2022-35707 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge 12.0.2/11.1.3 UA-FREE: Sensitive Data Leak via Malicious File
CVE-2022-38425 5.5 - Medium - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Dangling pointer

Adobe Bridge Heap BUF_OVF <12.0.2, <11.1.3 Leading to Arbitrary Code Exec
CVE-2022-35708 7.8 - High - September 19, 2022

Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Heap-based Buffer Overflow

Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file
CVE-2021-42722 7.8 - High - March 16, 2022

Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file
CVE-2021-42720 7.8 - High - March 16, 2022

Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .jpe file
CVE-2021-42719 7.8 - High - March 16, 2022

Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .jpe file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Out-of-bounds Read

Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file
CVE-2021-42533 7.8 - High - March 16, 2022

Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.

Double-free

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Adobe Bridge or by Adobe? Click the Watch button to subscribe.

Adobe
Vendor

Adobe Bridge
Product

subscribe