Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

Adobe Connect: Malicious Code Can Run in Your Browser

CVE-2026-27246
Summary

Adobe Connect software versions 2025.3 and earlier may allow a hacker to inject malicious code into your browser if you visit a specially crafted webpage. This could let the hacker access sensitive information or take control of your browser. Update to the latest version to fix this issue.

Original title
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to ex...
Original description
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
nvd CVSS3.1 9.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 14 Apr 2026 · Updated: 14 Apr 2026 · First seen: 14 Apr 2026