CVE-2026-27245Disclosure(adobe / connect)

MEDIUMCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for adobe connect systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect
  • connect_desktop_application
  • macos
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-14); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
connectconnect_desktop_applicationmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-14: 1Exploit Tool / Code · 2026-04-14: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-15: 104-1404-15
Signal classification1 categories
Disclosure
4100.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-143
Disclosure3
2026-04-151
Disclosure1
Full discourse4 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The text announces a security update covering multiple CVEs, providing technical details of the vulnerabilities but no PoC, patch, or evidence of active exploitation.

    000321.4K
    11.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27245 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to … https://www.cve.org/CVERecord?id=CVE-2026-27245

    Post summary

    The disclosed CVE-2026-27245 outlines a reflected XSS vulnerability affecting Adobe Connect versions up to 2025.3 and 12.10, providing technical details but no exploits, patches, or evidence of active exploitation.

    0000060
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27245: Adobe Connect | Cross-site Scrip... Adobe Connect's reflected XSS with scope change hits 9.3 CVSS - enterprise meeting rooms just became phishing goldmines... https://zerodaysignal.com/vulnerability/CVE-2026-27245 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts readers to a high‑severity reflected XSS vulnerability (CVE‑2026‑27245) in Adobe Connect, provides basic technical details and a CVSS score, and links to a zero‑day resource for further information.

    0000069
    218 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-27245 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. … CVSS 9.3 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-27245 #Adobe #CyberSecurity #InfoSec

    Post summary

    CVE-2026-27245 is a reflected XSS vulnerability in Adobe Connect with a CVSS score of 9.3, and no patch has yet been released.

    000000
    144 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeconnect---
Appadobeconnect_desktop_application-macos-
Appadobeconnect_desktop_application-windows-
OSapplemacos---
OSmicrosoftwindows---

Explore more