Reflected Cross-Site Scripting Vulnerability in Adobe Connect
CVE-2026-27245
9.3CRITICAL
What is CVE-2026-27245?
Adobe Connect versions 2025.3, 12.10, and earlier are vulnerable to a reflected Cross-Site Scripting (XSS) issue. This allows an attacker to exploit the vulnerability by enticing a user to click a specially crafted URL. If successful, malicious JavaScript code could be executed in the user's browser, potentially leading to unauthorized actions and data exposure. For comprehensive protection, it is critical for users to promptly update to the latest versions and follow recommended security practices.
Affected Version(s)
Adobe Connect 0 <= 12.10