
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27245 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect that allows unauthenticated attackers to inject malicious scripts into web pages viewed by victims. It affects Adobe Connect versions 2025.3, 12.10 and earlier (web application versions prior to 12.11), as well as the Adobe Connect Desktop Application for macOS up to version 2025.3 and for Windows prior to version 2025.9.15. The vulnerability was disclosed on April 14, 2026, with the CVE record modified by Adobe on April 27, 2026, to reflect an updated CVSS score. It carries a CVSS v3.1 base score of 9.3 (Critical), assigned by Adobe Systems Incorporated (Adobe Advisory, NVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the reflected XSS type (CAPEC-591). The root cause is insufficient sanitization of user-supplied input that is reflected back in HTTP responses, allowing an attacker to craft a malicious URL containing JavaScript payloads that execute in the victim's browser context. Exploitation requires no privileges and no authentication, but does require user interaction — the victim must visit a maliciously crafted URL or interact with a compromised web page. The scope is marked as "Changed," meaning the injected script can affect resources beyond the vulnerable application's security domain (NVD, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially gaining elevated access to or control over the victim's Adobe Connect account or session. The changed scope means the impact can extend beyond the Adobe Connect application itself, enabling session hijacking, credential theft, and unauthorized actions on behalf of the victim. Both confidentiality and integrity are rated as High impact, while availability is not affected; sensitive session data and account information are at risk of exposure or modification (NVD, Adobe Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Adobe Advisory). The EPSS score is approximately 0.097%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection coverage is available via Qualys (detection ID 733993) and Tenable.
https://target-connect-instance/vulnerable-page?param=<script>malicious_code_here</script> or an encoded equivalent to bypass basic filters.onerror, onload), or encoded XSS payloads in query parameters; unexpected outbound connections from client browsers to attacker-controlled domains following Adobe Connect page visits.<script>, javascript:, or encoded variants (e.g., %3Cscript%3E); repeated requests to the same endpoint with varying payload patterns indicative of probing.Adobe has released patched versions to address this vulnerability: Adobe Connect web application version 12.11 or later, and Adobe Connect Desktop Application version 2025.9.15 or later for Windows (macOS desktop application users should update to the latest available version). Organizations should prioritize upgrading to the patched versions as the primary remediation. As interim measures, administrators should advise users to avoid clicking unsolicited or suspicious Adobe Connect links, implement Content Security Policy (CSP) headers to reduce XSS attack surface, and conduct security awareness training. The official patch details are available in Adobe Security Bulletin APSB26-37 (Adobe Advisory).
The Center for Internet Security (CIS) published an advisory noting multiple vulnerabilities in Adobe products patched in April 2026, including this CVE, flagging the potential for arbitrary code execution-class impacts across the Adobe product suite. Fortress SRM included this vulnerability in their April 2026 threat and security update summary. A Mastodon post on infosec.exchange referenced the CVE, reflecting community awareness. No major independent researcher write-ups or significant social media controversy have been identified beyond standard vulnerability tracking and advisory coverage (CIS Advisory, Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."