CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution
Adobe Connect and its Android app contain SQL injection flaw CVE-2026-75682 with a CVSS score of 9.9, letting a low-privileged account achieve arbitrary code execution. Fixes shipped in Adobe Connect 12.12 and Android app 4.5; Adobe reported no known active exploitation.
- CVSS v3 score of 9.9, the highest in bulletin APSB26-150
- Attacker only needs a low-privileged account, no user interaction required
- Fixed in Adobe Connect 12.12 and Android app 4.5
- ZoomEye found 23,660 internet-reachable Adobe Connect instances
Read next
Security