PatchSiren cyber security CVE debrief
CVE-2026-75655 Adobe CVE debrief
CVE-2026-75655 is a high-severity Uncontrolled Recursion vulnerability affecting Adobe Bridge, potentially leading to arbitrary code execution. This CVE was published on 2026-09-22T19:16:45.383Z and was last modified on 2026-09-25T19:21:20.160Z. The NVD entry is currently Analyzed. The vulnerability requires user interaction, as a victim must open a malicious file. Defenders should assess exposure and apply patches due to the high CVSS score of 7.8. The vulnerability affects Adobe Bridge versions prior to 15.1.9 or 16.0.8.
- Vendor
- Adobe
- Product
- Bridge
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-25
Who should care
Defenders and administrators responsible for Adobe Bridge installations, as well as users who may interact with potentially malicious files, should assess exposure and apply patches.
Why it matters
CVE-2026-75655 is a high-severity vulnerability in Adobe Bridge that could lead to arbitrary code execution. Defenders should verify exposure, restrict user interactions with untrusted files, and apply patches to mitigate potential risks.
- Potential for arbitrary code execution requires verification of user interactions and file handling.
- High CVSS score of 7.8 indicates significant risk.
- Necessity to verify and apply patches to vulnerable versions.
Technical summary
The Uncontrolled Recursion vulnerability in Adobe Bridge could result in arbitrary code execution in the context of the current user when a malicious file is opened. This vulnerability affects Adobe Bridge versions prior to 15.1.9 or 16.0.8 and requires user interaction. The CVSS score of 7.8 indicates high severity, and defenders should prioritize verifying exposure and applying patches. The vulnerability can be mitigated by restricting user interactions with untrusted files and applying patches to vulnerable versions.
Defensive priority
Defenders should prioritize verifying exposure and applying patches due to the high CVSS score of 7.8 and potential for arbitrary code execution.
Recommended defensive actions
- Verify if Adobe Bridge versions prior to 15.1.9 or 16.0.8 are in use and apply patches if necessary.
- Review user interactions and restrict opening untrusted files.
- Monitor system logs for suspicious activity related to Adobe Bridge.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score and affected versions. Adobe has released a patch advisory for this issue. The vulnerability is tracked by CVE-2026-75655 and has a CVSS score of 7.8, indicating high severity. The NVD entry provides additional details on the vulnerability, including its impact and affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75655 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75655
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75655 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75655
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/bridge/apsb26-148.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.