CVE-2026-34660Disclosure(adobe / connect_desktop_application)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe connect_desktop_application systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect_desktop_application

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-05-12); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
connect_desktop_application

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-12: 2Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-31: 105-1205-1305-1405-31
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-123
Disclosure2Patch1
2026-05-131
Patch1
2026-05-141
Disclosure1
2026-05-311
General1
Full discourse6 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The post outlines several critical CVEs from Microsoft, Ivanti, Fortinet, SAP, and Adobe, highlighting technical details while emphasizing the necessity of applying the corresponding vendor patches.

    000211.4K
    11.7K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Adobe Patches 52 Vulnerabilities in 10 Products Adobe fixes 52 CVEs across 10 products including After Effects and Illustrator. Two are rated critical CVE-2026-34659 and CVE-2026-34660, both CVSS 9.x, arbitrary code execution vectors. No exploitation in the wild, but patch velocity is rising. Source: SecurityWeek / Adobe Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Adobe released patches for 52 vulnerabilities, including two critical CVEs with high CVSS scores, and no active exploitation has been observed.

    01010117
    181 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-34660: Adobe Connect Incorrect Authorization Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04jv5V90

    Post summary

    The text references CVE‑2026‑34660 as an incorrect authorization flaw in Adobe Connect, but provides no evidence of PoCs, exploits, active attacks, patches, or detailed technical data beyond the vulnerability type.

    0000041
    32 followersView on X
  • Daily Security Review@securitydailyr
    Disclosure

    Adobe May 2026: 52 vulnerabilities across 10 products. CVE-2026-34659 (CVSS 9.6 RCE) and CVE-2026-34660 (CVSS 9.3 LPE) in Adobe Connect. Adobe Commerce: Priority 2 — Magecart exploitation window is short. #CyberSecurity #PatchNow https://dailysecurityreview.com/cyber-security/adobe-may-2026-patches-connect-rce-cvss96/

    Post summary

    The post announces a batch of 52 new Adobe vulnerabilities, lists two high‑severity CVEs with RCE and LPE details, and notes a short window for potential Magecart exploitation.

    0000058
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34660 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the… https://www.cve.org/CVERecord?id=CVE-2026-34660

    Post summary

    The post announces that Adobe Connect versions up to 2025.9.15 are impacted by an incorrect authorization flaw that may allow arbitrary code execution. No PoC, exploit, or patch details are provided.

    00000168
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-34660 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that … CVSS 9.3 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-34660 #Adobe #CyberSecurity #InfoSec

    Post summary

    Adobe Connect is impacted by the high‑severity CVE‑2026‑34660 (Incorrect Authorization, CVSS 9.3); no patch is available yet, and a detailed analysis can be found at the provided link.

    0000071
    90 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeconnect_desktop_application-macos-
Appadobeconnect_desktop_application-windows-

Explore more