CVE-2026-27246Disclosure(adobe / connect)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe connect systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect
  • connect_desktop_application
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
connectconnect_desktop_applicationmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-15: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-15: 104-1404-1505-06
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-143
Disclosure2Patch1
2026-04-151
Disclosure1
2026-05-061
General1
Full discourse5 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The post lists several newly disclosed CVEs across multiple vendors, providing technical details and linking to vendor security update pages that presumably contain patches.

    000321.4K
    11.7K followersView on X
  • S2GRUPO@s2grupo
    General

    💥🖥️ CVE-2026-27303, CVE-2026-34615 y CVE-2026-27246 afectan a Adobe Connect, una plataforma muy utilizada en entornos corporativos para videoconferencias, formación online y colaboración remota. Descubre más sobre esta vulnerabilidad aquí: https://hubs.la/Q04dKd2n0

    Post summary

    The post lists three Adobe Connect CVEs and directs readers to a link for additional information, but provides no further technical or operational details.

    00010158
    5.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27246 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipul… https://www.cve.org/CVERecord?id=CVE-2026-27246

    Post summary

    The text announces a DOM-based XSS vulnerability in Adobe Connect 2025.3 and earlier, providing basic technical details but no PoC, exploit code, remediation suggestions, or evidence of active exploitation.

    0000061
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-27246 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. … CVSS 9.3 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-27246 #Adobe #CyberSecurity #InfoSec

    Post summary

    A critical vulnerability (CVE-2026-27246) affecting Adobe Connect has been disclosed with a DOM-based XSS flaw and a CVSS score of 9.3, but no patch or exploit code is currently available.

    000000
    144 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27246: Adobe Connect | Cross-site Scrip... DOM XSS in Adobe Connect with CVSS 9.3 and scope change means full session hijack across enterprise video conferences -... https://zerodaysignal.com/vulnerability/CVE-2026-27246 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces a new DOM XSS vulnerability, CVE-2026-27246, in Adobe Connect with a high CVSS score and potential for session hijack, but offers no PoC, exploit code, or patch details.

    0000061
    218 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeconnect---
Appadobeconnect_desktop_application-macos-
Appadobeconnect_desktop_application-windows-
OSapplemacos---
OSmicrosoftwindows---

Explore more