Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.1

Adobe Connect versions 2025.3 and earlier: Malicious scripts can run in your browser

CVE-2026-34614
Summary

Adobe Connect versions 2025.3 and earlier contain a security flaw that allows hackers to run malicious scripts in your browser if you visit a specially crafted link. This could potentially lead to your personal data being stolen or manipulated. Update to the latest version of Adobe Connect to fix this issue.

Original title
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulne...
Original description
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd CVSS3.1 6.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 14 Apr 2026 · Updated: 15 Apr 2026 · First seen: 14 Apr 2026