Deserialization of Untrusted Data in Adobe Connect
CVE-2026-34659

9.6CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34659?

Adobe Connect versions 2025.9.15 and 2025.8.157 and earlier versions are vulnerable to a deserialization of untrusted data issue. This vulnerability allows an attacker to execute arbitrary code within the context of the current user session. The exploitation of this vulnerability requires user interaction, as victims must either visit a maliciously crafted URL or interact with a compromised web page. This poses significant risks, necessitating immediate attention and mitigation.

Affected Version(s)

Adobe Connect 0 <= 2025.8.157

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.