CVE-2026-34659Disclosure(adobe / connect_desktop_application)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe connect_desktop_application systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect_desktop_application

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-05-12); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
connect_desktop_application

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-17: 1Mentions · 2026-05-29: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-17: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-29: 105-1205-1305-1405-1705-29
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-123
Disclosure2Patch1
2026-05-131
Disclosure1
2026-05-141
Patch1
2026-05-171
Disclosure1
2026-05-291
General1
Full discourse7 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The entry lists several newly disclosed high‑severity CVEs across multiple vendors with detailed technical descriptions but provides no PoC, exploit code, observed attacks, or patch information.

    000211.4K
    11.7K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Adobe Patches 52 Vulnerabilities in 10 Products Adobe fixes 52 CVEs across 10 products including After Effects and Illustrator. Two are rated critical CVE-2026-34659 and CVE-2026-34660, both CVSS 9.x, arbitrary code execution vectors. No exploitation in the wild, but patch velocity is rising. Source: SecurityWeek / Adobe Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Adobe has issued patches for 52 vulnerabilities across 10 products, including two critical CVEs with CVSS 9.x and arbitrary code execution, and reports no active exploitation in the wild.

    01010117
    181 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    🚨 CVE-2026-34659 (Adobe Connect ≤2025.8.157, CVSS 9.6): CWE-502 deserialization → RCE via malicious meeting URL. Gov, edu & healthcare at risk. No public PoC yet. Patch APSB26-50 dropped May 12 — flying under the radar. Admins: update NOW. #ZeroDay #Adobe

    Post summary

    Adobe Connect CVE-2026-34659 is a CVSS 9.6 RCE vulnerability caused by deserialization of malicious meeting URLs; a patch APSB26-50 is available, but no public PoC or evidence of in-the-wild exploitation has been reported.

    1000077
    226 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-34659: Adobe Connect Deserialization Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04jlzNq0

    Post summary

    The article announces the Adobe Connect deserialization flaw (CVE-2026-34659) and outlines general considerations for businesses, without detailing PoCs, exploits, or specific remediation steps.

    0000037
    31 followersView on X
  • Daily Security Review@securitydailyr
    Patch

    Adobe May 2026: 52 vulnerabilities across 10 products. CVE-2026-34659 (CVSS 9.6 RCE) and CVE-2026-34660 (CVSS 9.3 LPE) in Adobe Connect. Adobe Commerce: Priority 2 — Magecart exploitation window is short. #CyberSecurity #PatchNow https://dailysecurityreview.com/cyber-security/adobe-may-2026-patches-connect-rce-cvss96/

    Post summary

    Adobe announced a patch release for 52 vulnerabilities in May 2026, including two critical CVEs (CVE-2026-34659 RCE, CVE-2026-34660 LPE) affecting Adobe Connect and a brief Magecart exploitation window for Adobe Commerce.

    0000058
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34659 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code executi… https://www.cve.org/CVERecord?id=CVE-2026-34659

    Post summary

    The post announces a Deserialization of Untrusted Data vulnerability (CVE‑2026‑34659) in Adobe Connect that could lead to arbitrary code execution on affected versions.

    00000135
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-34659 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerabil… CVSS 9.6 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-34659 #Adobe #CyberSecurity #InfoSec

    Post summary

    A new critical vulnerability (CVE-2026-34659) affecting older Adobe Connect versions has been announced with a CVSS of 9.6, and no patch is available yet.

    0000047
    90 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeconnect_desktop_application-macos-
Appadobeconnect_desktop_application2025.9.15windows-

Explore more