CVE-2026-27245: Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27245?
CVE-2026-27245 is rated as a medium severity vulnerability due to its potential for exploitation through reflected XSS attacks.
How do I fix CVE-2026-27245?
To mitigate CVE-2026-27245, update Adobe Connect to version 2025.4 or later, which addresses the reflected XSS vulnerability.
What products are affected by CVE-2026-27245?
CVE-2026-27245 affects Adobe Connect versions 2025.3 and earlier, including 12.10 and earlier.
What kind of attack is possible with CVE-2026-27245?
CVE-2026-27245 allows attackers to perform reflected Cross-Site Scripting (XSS) attacks by tricking victims into visiting malicious URLs.
What should I do if I cannot immediately update to the latest version for CVE-2026-27245?
If an immediate update is not possible for CVE-2026-27245, restrict access to the affected services and educate users about the risks of clicking on suspicious links.