CVE-2026-21331: Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the reflected XSS by preventing access to vulnerable Adobe Connect pages until a vendor fix is applied (scope is changed; no specific patch or configuration details are provided in the material).
Event History
Frequently Asked Questions
What is the vulnerability type of CVE-2026-21331?
CVE-2026-21331 is a reflected Cross-Site Scripting (XSS) vulnerability.
What are the affected versions for CVE-2026-21331?
Adobe Connect versions 2025.3, 12.10 and earlier are affected by CVE-2026-21331.
What could an attacker achieve by exploiting CVE-2026-21331?
An attacker could execute malicious JavaScript in the context of a victim's browser by exploiting CVE-2026-21331.
How can users protect themselves from CVE-2026-21331?
Users can protect themselves by avoiding clicking on suspicious links that may lead to vulnerable Adobe Connect pages.
Is there a patch available for CVE-2026-21331?
Yes, Adobe has released updates to fix CVE-2026-21331 in the affected versions of Adobe Connect.