PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75655 Adobe CVE debrief

CVE-2026-75655 is a high-severity Uncontrolled Recursion vulnerability affecting Adobe Bridge, potentially leading to arbitrary code execution. This CVE was published on 2026-09-22T19:16:45.383Z and was last modified on 2026-09-25T19:21:20.160Z. The NVD entry is currently Analyzed. The vulnerability requires user interaction, as a victim must open a malicious file. Defenders should assess exposure and apply patches due to the high CVSS score of 7.8. The vulnerability affects Adobe Bridge versions prior to 15.1.9 or 16.0.8.

Vendor
Adobe
Product
Bridge
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-22
Original CVE updated
2026-09-25
Advisory published
2026-09-22
Advisory updated
2026-09-25

Who should care

Defenders and administrators responsible for Adobe Bridge installations, as well as users who may interact with potentially malicious files, should assess exposure and apply patches.

Why it matters

CVE-2026-75655 is a high-severity vulnerability in Adobe Bridge that could lead to arbitrary code execution. Defenders should verify exposure, restrict user interactions with untrusted files, and apply patches to mitigate potential risks.

  • Potential for arbitrary code execution requires verification of user interactions and file handling.
  • High CVSS score of 7.8 indicates significant risk.
  • Necessity to verify and apply patches to vulnerable versions.

Technical summary

The Uncontrolled Recursion vulnerability in Adobe Bridge could result in arbitrary code execution in the context of the current user when a malicious file is opened. This vulnerability affects Adobe Bridge versions prior to 15.1.9 or 16.0.8 and requires user interaction. The CVSS score of 7.8 indicates high severity, and defenders should prioritize verifying exposure and applying patches. The vulnerability can be mitigated by restricting user interactions with untrusted files and applying patches to vulnerable versions.

Defensive priority

Defenders should prioritize verifying exposure and applying patches due to the high CVSS score of 7.8 and potential for arbitrary code execution.

Recommended defensive actions

  • Verify if Adobe Bridge versions prior to 15.1.9 or 16.0.8 are in use and apply patches if necessary.
  • Review user interactions and restrict opening untrusted files.
  • Monitor system logs for suspicious activity related to Adobe Bridge.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score and affected versions. Adobe has released a patch advisory for this issue. The vulnerability is tracked by CVE-2026-75655 and has a CVSS score of 7.8, indicating high severity. The NVD entry provides additional details on the vulnerability, including its impact and affected versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75655 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75655

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75655 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75655

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.