Adobe patches nine flaws in Connect and its Android app
Adobe released APSB26-150 fixes for Adobe Connect 12.12 and the Connect Android app 4.5. The headline flaw is CVE-2026-75682, a SQL injection rated 9.9 that can lead to code execution; five more flaws score 9.3. Adobe said it was not aware of active exploitation.
- CVE-2026-75682: SQL injection rated 9.9, needs a low-privileged account
- Five flaws score 9.3, three of them stored XSS leading to privilege escalation
- CVE-2026-34689 is an 8.6 path traversal requiring no authentication
- ZoomEye found 23,660 Adobe Connect instances exposed online
Read next
Security