CVE-2026-21331: Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability type of CVE-2026-21331?
CVE-2026-21331 is a reflected Cross-Site Scripting (XSS) vulnerability.
What are the affected versions for CVE-2026-21331?
Adobe Connect versions 2025.3, 12.10 and earlier are affected by CVE-2026-21331.
What could an attacker achieve by exploiting CVE-2026-21331?
An attacker could execute malicious JavaScript in the context of a victim's browser by exploiting CVE-2026-21331.
How can users protect themselves from CVE-2026-21331?
Users can protect themselves by avoiding clicking on suspicious links that may lead to vulnerable Adobe Connect pages.
Is there a patch available for CVE-2026-21331?
Yes, Adobe has released updates to fix CVE-2026-21331 in the affected versions of Adobe Connect.