Reflected Cross-Site Scripting Vulnerability in Adobe Connect
CVE-2026-21331
6.1MEDIUM
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-21331?
Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability in versions 2025.3, 12.10, and earlier. This vulnerability allows attackers to exploit the system by convincing users to visit a crafted URL. If successful, malicious JavaScript can be executed in the context of the victim's browser, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
Adobe Connect 0 <= 12.10
Adobe Connect Desktop Application 0 <= 2025.3
Adobe Connect 12.11