High severity7.8NVD Advisory· Published Jul 28, 2026· Updated Aug 3, 2026
CVE-2026-48392
CVE-2026-48392
Description
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected products
2cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*range: <15.1.7
- (no CPE)
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/bridge/apsb26-89.htmlnvdPatchVendor Advisory
News mentions
2- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionThe Hacker News · Aug 1, 2026
- Adobe Bridge: Eight High-Severity Flaws Disclosed Together Allow Code ExecutionVypr Intelligence · Jul 28, 2026