Adobe released security updates for nine high-severity vulnerabilities affecting Adobe Bridge and Adobe Format Plugins, including CVE-2026-48390, an incorrect authorization flaw in Bridge that can enable privilege escalation and unauthorized read and write access when a user opens a malicious file. The issues also include vulnerabilities that could lead to arbitrary code execution, affecting software used to manage, organize, and process digital content and file formats.
Affected versions include Adobe Bridge 15.x before 15.1.7 LTS, 16.x before 16.0.6, and Format Plugins before 2026.05. Adobe lists Bridge 15.1.7 and 16.0.6 as fixed versions for the authorization bug, which carries a CVSS v3.1 vector of AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N, indicating high confidentiality and integrity impact with required user interaction. Users are being urged to apply the vendor updates to reduce the risk of code execution and privilege escalation from malicious files.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Adobe released security updates addressing nine high-severity vulnerabilities in Adobe Bridge and Format Plugins, including CVE-2026-48390. The updates affect Adobe Bridge 15.x before 15.1.7 LTS, Adobe Bridge 16.x before 16.0.6, and Format Plugins before version 2026.05.
CVE-2026-48390 was newly recorded as an Incorrect Authorization flaw in Adobe Bridge that can enable privilege escalation and unauthorized read and write access when a victim opens a malicious file. The record identifies Adobe Bridge versions up to 16.0.5 and 15.1.6 as affected, with versions 16.0.6 and 15.1.7 listed as unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.