Adobe Connect: three stored XSS flaws rated 9.3
Adobe's September 2026 Connect update fixes nine flaws, including three stored XSS bugs (CVE-2026-75684, CVE-2026-75689, CVE-2026-75697) rated CVSS 9.3 that lead to privilege escalation and need no authentication. The fix is Adobe Connect 12.12 with the Android client at 4.5.
- Three CVEs carry a CVSS score of 9.3 and require no authentication
- Stored XSS runs in an admin session, enabling privilege escalation
- CVE-2026-75686 and CVE-2026-75698 also fixed for code execution
- ZoomEye found 23,660 reachable Adobe Connect instances
Read next
Security