Reflected Cross-Site Scripting Vulnerability in Adobe Connect
CVE-2026-27243

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 April 2026

What is CVE-2026-27243?

Adobe Connect versions 2025.3, 12.10, and earlier are impacted by a reflected Cross-Site Scripting vulnerability. This flaw could be exploited if an attacker tricks a user into clicking a crafted URL that references a vulnerable page. Once successful, the malicious JavaScript can execute within the user’s browser, potentially leading to unauthorized actions or data exposure. Users and admins are encouraged to update to the latest version to mitigate this risk and ensure a secure environment.

Affected Version(s)

Adobe Connect 0 <= 12.10

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.