Adobe Releases Patches for Multiple Critical Vulnerabilities

Adobe released two security advisories addressing nine vulnerabilities affecting the Adobe Bridge and Adobe Format Plugins. All these vulnerabilities have critical severity ratings given by Adobe.

Adobe Bridge is a free digital asset manager and file browser created by Adobe Inc. It allows users to preview, organize, and batch-process creative files without requiring a formal import process.

Adobe format plugins are specialized software add-ons that enable Adobe applications such as Photoshop, After Effects, or Analytics to open, save, or process specific and uncommon file types or data formats. They bridge software gaps so programs can read data they do not normally support by default.

CVE-2026-48372

This is a heap-based buffer overflow vulnerability in Adobe Format Plugins that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48395

This is an untrusted search path vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48396

This is an incorrect authorization vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48390

This is an incorrect authorization vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48391

This is an untrusted search path vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48374

This is a path traversal vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48392

This is an out-of-bounds write vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48393

This is an out-of-bounds write vulnerability in Adobe Bridge that may allow an attacker to achieve arbitrary code execution upon successful exploitation.

CVE-2026-48394

This is an out-of-bounds write vulnerability in Adobe Bridge that could allow an attacker to execute arbitrary code upon successful exploitation.

Affected and Patched Versions

Product Affected Versions Platform Patched Versions
Adobe Format Plugins 2026.05 and earlier versions All 2026.07
Adobe Bridge  15.1.6 (LTS) and earlier versions Windows & macOS 15.1.7 (LTS)
Adobe Bridge  16.0.5 and earlier versions Windows & macOS 16.0.6

For more information, please refer to the Adobe Security Advisories for Adobe Format Plugins and Adobe Bridge.

Qualys Detection

Qualys customers can scan their devices with QID 388164 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://helpx.adobe.com/security/products/bridge/apsb26-89.html
https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html