CVE-2026-27303Disclosure(adobe / connect)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe connect systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect
  • connect_desktop_application
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-04-14); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Products
connectconnect_desktop_applicationmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-15: 2Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-28: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-15: 2Technical Details · 2026-04-17: 1Technical Details · 2026-04-28: 104-1404-1504-1704-1804-2805-06
Signal classification3 categories
Disclosure
444.4%
Patch
333.3%
General
222.2%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-04-143
Disclosure2Patch1
2026-04-152
Disclosure2
2026-04-171
Patch1
2026-04-181
General1
2026-04-281
Patch1
2026-05-061
General1
Full discourse9 posts
  • Wazuh@wazuh
    Patch

    Adobe Connect is affected by CVE-2026-27303 (CVSS 10.0), a critical deserialization flaw that may allow remote code execution without user interaction. Affects versions ≤12.10 and desktop versions ≤2025.3. Update to 12.11+ and desktop 2025.9+. Read on: https://cti.wazuh.com/vulnerabilities/cves/CVE-2026-27303 https://t.co/jPB2EX7zG3

    Post summary

    Adobe Connect is vulnerable to a critical deserialization flaw (CVE-2026-27303) that could lead to remote code execution; users are advised to upgrade to the specified newer versions.

    070195985
    8.1K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The post enumerates recent CVEs across multiple vendors, offering technical details of the weaknesses and linking to the respective security update or advisory pages.

    000321.4K
    11.7K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🎨 منتجات Adobe: 🎥 منتج Adobe Connect: التقييم: 9.6 | (CVE-2026-27303, 34615) ⚠️ تحديثات طارئة لسد ثغرات (Deserialization RCE). ❄️ منتج Adobe ColdFusion: التقييم: 9.3 | (CVE-2026-27304) ⚠️ تجاوز التحقق من المدخلات (Input Validation Bypass).

    Post summary

    Emergency patch updates are announced for Adobe Connect (CVE-2026-27303) and Adobe ColdFusion (CVE-2026-27304), covering Deserialization RCE and Input Validation Bypass vulnerabilities.

    100011.6K
    48.7K followersView on X
  • S2GRUPO@s2grupo
    General

    💥🖥️ CVE-2026-27303, CVE-2026-34615 y CVE-2026-27246 afectan a Adobe Connect, una plataforma muy utilizada en entornos corporativos para videoconferencias, formación online y colaboración remota. Descubre más sobre esta vulnerabilidad aquí: https://hubs.la/Q04dKd2n0

    Post summary

    The post lists three CVEs affecting Adobe Connect and directs users to a link for more information, but provides no substantive details on exploitation, patches, or technical specifics.

    00010158
    5.1K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-27303 2 - CVE-2026-34197 3 - CVE-2026-5194 4 - CVE-2026-4365 5 - CVE-2026-34621 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVE identifiers without providing any additional technical context or actionable information.

    00010174
    1.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-27303 — CVSS 9.6/10 ██████████ Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/USs6tbyHve

    Post summary

    A critical deserialization vulnerability (CVE-2026-27303) affects Adobe Connect; a patch is available and recommended.

    1000044
    23 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27303 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in th… https://www.cve.org/CVERecord?id=CVE-2026-27303

    Post summary

    The post announces CVE-2026-27303, detailing a deserialization-based arbitrary code execution flaw in Adobe Connect, but provides no PoC, exploit, or patch information.

    0000061
    57.2K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Adobe Connect | Deserialization of Untrusted Data (CWE-502) CVE: CVE-2026-27303 PT ID: PT-2026-32767 Vendor: Adobe Product: Adobe Connect CVSS: 9.6 Credits: n/a Description: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27303 • https://helpx.adobe.com/security/products/connect/apsb26-37.html #dbugs_vuln

    Post summary

    Adobe Connect has been disclosed to contain a deserialization flaw (CVE‑2026‑27303) that can lead to arbitrary code execution, rated CVSS 9.6, with no PoC or exploit details shared yet.

    0000054
    797 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-27303 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that… CVSS 9.6 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-27303 #Adobe #CyberSecurity #InfoSec

    Post summary

    The post announces a critical CVE‑2026‑27303 affecting Adobe Connect, giving its severity (CVSS 9.6) and noting that no patch is yet available.

    000000
    144 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeconnect---
Appadobeconnect_desktop_application-macos-
Appadobeconnect_desktop_application-windows-
OSapplemacos---
OSmicrosoftwindows---

Explore more