CVE-2026-27243: Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27243?
CVE-2026-27243 is rated as a medium severity vulnerability due to its potential for exploitation through reflected XSS attacks.
How do I fix CVE-2026-27243?
To fix CVE-2026-27243, upgrade Adobe Connect to version 2025.4 or later.
What versions of Adobe Connect are affected by CVE-2026-27243?
CVE-2026-27243 affects Adobe Connect versions 2025.3 and 12.10 and earlier.
What type of attack does CVE-2026-27243 enable?
CVE-2026-27243 enables reflected cross-site scripting (XSS) attacks.
Who is impacted by CVE-2026-27243?
Users of Adobe Connect versions 2025.3 and 12.10 and earlier are at risk from CVE-2026-27243.