Junglewise Threat Intelligence

CVE-2026-27313: Adobe Bridge heap overflow in file processing

CVE-2026-27313 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe Bridge. Vendors: Adobe.

Executive brief

Adobe Bridge, a digital asset management application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or software with the same permissions as the logged-in user.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe Bridge versions 15.1.4, 16.0.2, and earlier. The flaw is triggered when the application improperly handles memory during the processing of a specially crafted file. An attacker can exploit this by convincing a victim to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R). Adobe has addressed this in versions 15.1.5 and 16.0.3.

Affected products

  • Adobe Bridge <= 15.1.4, 16.0.0 to 16.0.2

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe published security bulletin APSB26-39

References

Related threats