Adobe Connect patches nine critical vulnerabilities
Adobe fixed 9 flaws in Adobe Connect and its Android app, including a 9.9-CVSS SQL injection allowing arbitrary code execution; no active exploitation reported.
NCSC-NL published an advisory summarizing Adobe's security update for Adobe Connect (fixed in version 12.12) and the Adobe Connect Android Mobile App (fixed in version 4.5), addressing nine vulnerabilities spanning SQL injection, stored and reflected cross-site scripting, insufficient input validation, path traversal, and improper certificate validation. Seven of the nine flaws are rated critical by Adobe, with six scoring 9.3 or higher on CVSS v3. The most severe, CVE-2026-75682 (CVSS 9.9), is a SQL injection flaw allowing a low-privileged attacker to execute arbitrary code. Three stored XSS vulnerabilities (CVE-2026-75684, CVE-2026-75689, CVE-2026-75697) can lead to privilege escalation, while CVE-2026-75686 (insufficient input validation) and CVE-2026-75698 (reflected XSS) can also result in arbitrary code execution. These five require user interaction but no authentication. A separate path traversal flaw, CVE-2026-34689 (CVSS 8.6), allows an unauthenticated attacker to read arbitrary files without any user interaction required.
Adobe states it is not aware of active exploitation of any of these vulnerabilities in the wild. Defenders running Adobe Connect should prioritize patching to version 12.12 and update the Android mobile app to version 4.5. Given the number of critical-rated flaws and the low complexity of exploitation for several (including unauthenticated file read and code execution paths), organizations using Adobe Connect for web conferencing should treat this update as high priority even absent confirmed in-the-wild attacks.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0391.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free