---
id: CVE-2026-21347
title: >-
  Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow
  or Wraparound vulnerability that could result in arbitrary code execution in
  the context of the current user
summary: >-
  Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow
  or Wraparound vulnerability that could result in arbitrary code execution in
  the context of the current user. Exploitation of this issue requires user
  interac…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: adobe
product: bridge
affected:
  - bridge < 15.1.4
  - 'bridge >= 16.0, < 16.0.2'
patched:
  - bridge 16.0.2
published: '2026-02-10'
updated: '2026-08-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21347'
references:
  - url: 'https://helpx.adobe.com/security/products/bridge/apsb26-21.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00165
epssPercentile: 0.04999
ingestedAt: '2026-08-27T21:08:16.907Z'
---

## Overview

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `bridge < 15.1.4`
- `bridge >= 16.0, < 16.0.2`

## Remediation

Upgrade past the affected range:

- `bridge 16.0.2`
