Stored Cross-Site Scripting Vulnerability in Adobe Connect by Adobe
CVE-2026-75684

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-75684?

Adobe Connect is susceptible to a stored Cross-Site Scripting (XSS) vulnerability that enables attackers to inject harmful scripts into vulnerable form fields. If a user accesses the compromised page that contains these fields, malicious JavaScript could execute within their browser, leading to unauthorized access or control over the user’s session and sensitive information.

Affected Version(s)

Adobe Connect 0 <= 12.11

Adobe Connect Android Mobile App 0 <= 4.4

Adobe Connect 12.11.1, 12.12

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.