Adobe Security Bulletin

Security update available for Adobe Connect  | APSB26-150

Bulletin ID

Date Published

Priority

APSB26-150

September 22, 2026

2

Summary

Adobe has released a security update for Adobe Connect. This update resolves critical and important vulnerabilities that could result in arbitrary code execution, arbitrary file system read, privilege escalation, and security feature bypass.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Affected Product Versions

Product

Version

Platform

Adobe Connect

12.11 and earlier

Windows and macOS

Adobe Connect Android Mobile App

4.4 and earlier

Android

Solution

Adobe categorizes these updates with the following  priority ratings and recommends users update their installation to the latest version.

Product

Version

Platform

Priority

Availability

Adobe Connect 

12.12

Windows and macOS

2

Adobe Connect Android Mobile App 

4.5

Android

2

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-75682

Cross-site Scripting (Stored XSS) (CWE-79)

Privilege escalation

Critical

9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CVE-2026-75684

Improper Input Validation (CWE-20)

Arbitrary code execution

Critical

9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CVE-2026-75686

Cross-site Scripting (Stored XSS) (CWE-79)

Privilege escalation

Critical

9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CVE-2026-75689

Cross-site Scripting (Stored XSS) (CWE-79)

Privilege escalation

Critical

9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CVE-2026-75697

Cross-site Scripting (Reflected XSS) (CWE-79)

Arbitrary code execution

Critical

9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CVE-2026-75698

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Arbitrary file systeam read

Critical

8.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CVE-2026-34689

Improper Certificate Validation (CWE-295) Security feature bypass Important 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2026-83964

Cross-site Scripting (Stored XSS) (CWE-79)

Arbitrary code execution

Important

6.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2026-48361

Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Acknowledgments

Adobe would like to thank the following researchers for reporting these issue and for working with Adobe to help protect our customers:   

  • Diego (goedix) — CVE-2026-75682
  • Tomi (archyxsec) — CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697
  • Jim Green (green-jam) — CVE-2026-75698
  • curiositysec — CVE-2026-34689
  • Sergio Framinan Garcia (sergioframi) — CVE-2026-48361

For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com.

Adobe, Inc.

Get help faster and easier

New user?