Junglewise Threat Intelligence

CVE-2026-21347: Adobe Bridge integer overflow

CVE-2026-21347 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Bridge. Vendors: Adobe.

Executive brief

Adobe Bridge is a file browser and asset management application used by designers to organize and preview digital files. An integer overflow vulnerability in this application allows attackers to execute arbitrary code if a user opens a specially crafted malicious file, potentially compromising the designer's system and sensitive creative assets.

Technical details

This vulnerability is an integer overflow or wraparound condition in Adobe Bridge versions 15.1.3, 16.0.1 and earlier. The flaw allows an attacker to craft a malicious file that, when opened by a user in Bridge, triggers integer arithmetic that wraps around and causes memory corruption. This memory corruption can be leveraged to achieve arbitrary code execution in the context of the current user. The attack requires user interaction (opening the malicious file) and does not require authentication or network access. No known public exploits have been reported as of the advisory date.

Affected products

  • Adobe Bridge 15.1.3, 16.0.1 and earlier

Timeline

  • 2026-02-10: disclosed
  • 2026-02-10: advisory: APSB26-21

References

Related threats