Bulletin ID
Security update available for Adobe Connect | APSB26-150
|
|
Date Published |
Priority |
|---|---|---|
|
APSB26-150 |
September 22, 2026 |
2 |
Summary
Adobe has released a security update for Adobe Connect. This update resolves critical and important vulnerabilities that could result in arbitrary code execution, arbitrary file system read, privilege escalation, and security feature bypass.
Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.
Affected Product Versions
|
Product |
Version |
Platform |
|---|---|---|
|
Adobe Connect |
12.11 and earlier |
Windows and macOS |
|
Adobe Connect Android Mobile App |
4.4 and earlier |
Android |
Solution
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the latest version.
|
Product |
Version |
Platform |
Priority |
Availability |
|---|---|---|---|---|
|
Adobe Connect |
12.12 |
Windows and macOS |
2 |
|
|
Adobe Connect Android Mobile App |
4.5 |
Android |
2 |
Vulnerability Details
| Vulnerability Category | Vulnerability Impact | Severity | CVSS base score | CVSS vector | CVE Number |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-75682 |
Cross-site Scripting (Stored XSS) (CWE-79) |
Privilege escalation |
Critical |
9.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
CVE-2026-75684 |
Improper Input Validation (CWE-20) |
Arbitrary code execution |
Critical |
9.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
CVE-2026-75686 |
Cross-site Scripting (Stored XSS) (CWE-79) |
Privilege escalation |
Critical |
9.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
CVE-2026-75689 |
Cross-site Scripting (Stored XSS) (CWE-79) |
Privilege escalation |
Critical |
9.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
CVE-2026-75697 |
Cross-site Scripting (Reflected XSS) (CWE-79) |
Arbitrary code execution |
Critical |
9.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
CVE-2026-75698 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
Arbitrary file systeam read |
Critical |
8.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
CVE-2026-34689 |
| Improper Certificate Validation (CWE-295) | Security feature bypass | Important | 6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | CVE-2026-83964 |
Cross-site Scripting (Stored XSS) (CWE-79) |
Arbitrary code execution |
Important |
6.1 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
CVE-2026-48361 |
Acknowledgments
Adobe would like to thank the following researchers for reporting these issue and for working with Adobe to help protect our customers:
- Diego (goedix) — CVE-2026-75682
- Tomi (archyxsec) — CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697
- Jim Green (green-jam) — CVE-2026-75698
- curiositysec — CVE-2026-34689
- Sergio Framinan Garcia (sergioframi) — CVE-2026-48361
For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com.