Stored XSS Vulnerability in Adobe Connect Product
CVE-2026-75689

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-75689?

Adobe Connect is susceptible to a stored Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject harmful scripts into form fields. If exploited, this flaw could lead to the execution of malicious JavaScript in a victim's browser when they access a web page containing the compromised field. Consequently, an attacker could gain unauthorized access or control over the victim’s account or session. It is crucial for users to apply necessary security measures to protect against such risks.

Affected Version(s)

Adobe Connect 0 <= 12.11

Adobe Connect Android Mobile App 0 <= 4.4

Adobe Connect 12.11.1, 12.12

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.