Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

Adobe Connect: Visitor's Browser Can Run Malicious Code

CVE-2026-27243
Summary

Adobe Connect versions 2025.3 and earlier have a security flaw that could let an attacker trick someone into visiting a special website. If this happens, the attacker's malicious code can run on the victim's computer, potentially stealing sensitive information or causing other harm. Update to the latest version to protect your users.

Original title
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulne...
Original description
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd CVSS3.1 9.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 14 Apr 2026 · Updated: 14 Apr 2026 · First seen: 14 Apr 2026