Adobe Connect Desktop Application vulnerabilities
11 known vulnerabilities affecting adobe/connect_desktop_application.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-34660CRITICALCVSS 9.3≤ 2025.8.157≤ 2025.9.152026-05-12
CVE-2026-34660 [CRITICAL] CWE-863 CVE-2026-34660: Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's
nvd
CVE-2026-34659CRITICALCVSS 9.6≤ 2025.8.157v2025.9.152026-05-12
CVE-2026-34659 [CRITICAL] CWE-502 CVE-2026-34659: Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrus
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim mu
nvd
CVE-2026-27245CRITICALCVSS 9.3≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-27245 [CRITICAL] CWE-79 CVE-2026-27245: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-27303CRITICALCVSS 9.6≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-27303 [CRITICAL] CWE-502 CVE-2026-27303: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scop
nvd
CVE-2026-27243CRITICALCVSS 9.3≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-27243 [CRITICAL] CWE-79 CVE-2026-27243: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-34615CRITICALCVSS 9.3≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-34615 [CRITICAL] CWE-502 CVE-2026-34615: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim
nvd
CVE-2026-27246CRITICALCVSS 9.3≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-27246 [CRITICAL] CWE-79 CVE-2026-27246: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-34617HIGHCVSS 8.7≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-34617 [HIGH] CWE-79 CVE-2026-34617: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulner
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation o
nvd
CVE-2026-21331MEDIUMCVSS 6.1≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-21331 [MEDIUM] CWE-79 CVE-2026-21331: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd
CVE-2026-34614MEDIUMCVSS 6.1≤ 2025.3fixed in 2025.9.152026-04-14
CVE-2026-34614 [MEDIUM] CWE-79 CVE-2026-34614: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd
CVE-2025-27203CRITICALCVSS 9.6fixed in 2025.5.52025-07-08
CVE-2025-27203 [CRITICAL] CWE-502 CVE-2025-27203: Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerab
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed.
nvd