Junglewise Threat Intelligence

CVE-2026-75655: Adobe Bridge uncontrolled recursion arbitrary code execution

CVE-2026-75655 · Severity: high · CVSS 7.8 · Published 2026-09-22

Technologies: Adobe Bridge. Vendors: Adobe.

Executive brief

Adobe Bridge, a digital asset management application used by creative professionals to organize and preview media files, contains an uncontrolled recursion vulnerability that could allow an attacker to execute arbitrary code with the privileges of the current user. An attacker could exploit this by crafting a malicious file and tricking a user into opening it, leading to code execution and potential compromise of the user's system.

Technical details

The vulnerability is an uncontrolled recursion flaw in Adobe Bridge that can be triggered through a specially crafted input file. Exploitation requires user interaction: a victim must manually open a malicious file. Successful exploitation grants arbitrary code execution in the context of the current user.

Affected products

  • Adobe Bridge

Timeline

  • 2026-09-22: disclosed

References

Related threats