CVE-2026-27222
published 2026-04-14CVE-2026-27222: Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.18%
7.5th percentile
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | bridge | < 15.1.5 | 15.1.5 |
| adobe | bridge | <= 15.1.4 | — |
| adobe | bridge | >= 16.0 < 16.0.3 | 16.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pgvh-5499-q39c: Bridge versions 16
ghsa_unreviewed·2026-04-14
CVE-2026-27222 [MEDIUM] CWE-369 GHSA-pgvh-5499-q39c: Bridge versions 16
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe Bridge up to 15.1.4/16.0.2 File divide by zero (apsb26-39)
vuldb·2026-04-14·CVSS 5.5
CVE-2026-27222 [MEDIUM] Adobe Bridge up to 15.1.4/16.0.2 File divide by zero (apsb26-39)
A vulnerability described as problematic has been identified in Adobe Bridge up to 15.1.4/16.0.2. Affected by this issue is some unknown functionality of the component File Handler. The manipulation results in divide by zero.
This vulnerability is known as CVE-2026-27222. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published