cbcvebase.
CVE-2026-48391
published 2026-07-28

CVE-2026-48391: Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged…

PriorityP340high8.2CVSS 3.1
AVLACLPRLUIRSCCHIHAH
EPSS
0.15%
5.2th percentile
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected

3 ranges
VendorProductVersion rangeFixed in
adobeadobe_bridge<= 16.0.5
adobebridge< 15.1.715.1.7
adobebridge>= 16.0 < 16.0.616.0.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.